@vendure/core is vulnerable to Server-side Request Forgery (SSRF)
81
High Risk
DefaultAssetImportStrategy.getStreamFromUrl previously fetched any URL supplied by an admin without checking what host it actually resolves to. Combined with Node's permissive http.get, this gave an authenticated admin a free SSRF primitive: pointing the importer at e.g. http://foo-bar/latest/meta-data/ extracts cloud IAM tokens, and any hostname pointing at a loopback / RFC 1918 / link-local address could probe internal services that trust same-host traffic.
You are affected if you are using a version that falls within the vulnerable range.
@vendure/core is vulnerable to Server-side Request Forgery (SSRF) in versions 1.0.0 - 3.6.3.
Upgrade the @vendure/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant