Description
The lookup function takes a user address for checking accounts as a feature, however, as per the ActivityPub spec (https://www.w3.org/TR/activitypub/#security-considerations), on the security considerations section at B.3, access to Localhost services should be prevented while running in production.
Recommendation
Update the webfinger.js package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.8.0
- Patched version(s): 2.8.1
References
Related Issues
- Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability - CVE-2025-15104
- Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering - CVE-2025-54075
- content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE - CVE-2025-55164
- gifplayer XSS vulnerability - CVE-2025-31128
You might also like:
- Tags:
- npm
- webfinger.js
Anything's wrong? Let us know Last updated on August 01, 2025


