Executive brief
TerriaJS-Server is a mapping and geospatial data visualization platform that includes a proxy feature to fetch content from external domains. A validation flaw in the domain allowlist check allows attackers to bypass proxy restrictions by registering domains that end with allowed hostnames (e.g., if "example.com" is allowed, "maliciousexample.com" is also incorrectly permitted). An attacker could exploit this to proxy unauthorized content, potentially enabling phishing, malware delivery, or data exfiltration through the compromised server.
Technical details
TerriaJS-Server's proxy allowlist validation implements an incomplete domain-matching check using only a string suffix comparison (checking if a hostname ends with an allowed domain). This allows an attacker to craft a domain like "maliciousexample.com" that passes validation if "example.com" is in the allowlist. No authentication or user interaction is required; the vulnerability is exploitable remotely by any unauthenticated attacker. By registering an attacker-controlled domain matching this pattern, an adversary can proxy arbitrary content through the compromised TerriaJS-Server instance. The vulnerability affects all versions up to 4.0.2; version 4.0.3 and later contain the fix.
Affected products
- TerriaJS TerriaJS-Server < 4.0.3
Timeline
- 2026-02-26: disclosed: Vulnerability published in GitHub Security Advisory
- 2026-02-26: patched: Version 4.0.3 released with fix