webfinger.js is vulnerable to Server-Side Request Forgery (SSRF)
66
Medium Risk
Affected versions of this package are vulnerable to server-side request forgery (SSRF) due to improper parsing and validation of user-supplied WebFinger addresses. The affected lookup logic derives request targets from externally controlled input without sufficiently restricting host, path, or private network destinations, allowing crafted addresses to redirect outbound requests to localhost, internal services, or arbitrary endpoints. An attacker able to supply malicious lookup values can cause the application to initiate unauthorized network requests, potentially exposing internal resources or enabling blind SSRF attacks.
You are affected if you are using a version that falls within the vulnerable range.
webfinger.js is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 3.0.3.
Upgrade the webfinger.js library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant