GHSA-r95q-fp26-h3hc
HIGHCVE-2026-55177Every route in the ESRI helper family (api/routes/esri.ts) takes a fully attacker-controlled URL from the request (POST /api/esri body url, and the portal / server / layer query parameters on the GET /api/esri/ routes) and passes it into EsriBase / EsriProxyPortal / EsriProxyServer / EsriProxyLayer in api/lib/esri.ts, which fetch it with the bare fetch from @tak-ps/etl. No IP / DNS / hostname clas
- Affected
- >=0, <13.10.0, < 13.10.0
- Fixed in
- 13.10.0
- Weakness
- CWE-918
- Published
- 2026-07-17
- Source
- osv