Executive brief
Uppy Companion is a backend service module used to handle file uploads and remote source fetches in Uppy file upload systems. An attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability in the private IP address validation by using IPv4-mapped IPv6 address notation to bypass security checks and access internal services or private networks that should be blocked.
Technical details
The vulnerability exists in Uppy Companion's IP address filtering logic, which fails to properly validate IPv4-mapped IPv6 addresses (e.g., ::FFFF:127.0.0.1). An attacker can craft requests using this notation to bypass the private IP check and perform server-side requests to restricted internal resources. The flaw affects all versions prior to 3.1.5 and requires only network reachability to the Companion service with no authentication or user interaction. An attacker can use this to scan internal networks, access private services, or perform actions on behalf of the Companion server. The vulnerability was patched in version 3.1.5 via an improved private IP check mechanism.
Affected products
- Transloadit Uppy Companion before 3.1.5
Timeline
- 2022-01-06: disclosed: GHSA-x8rq-rc7x-5fg5 published
- 2022-01-04: patched: Fixed in version 3.1.5