Vulnerabilities/

webfinger.js Blind SSRF Vulnerability

Severity:
Medium

Description

The lookup function takes a user address for checking accounts as a feature, however, as per the ActivityPub spec (https://www.w3.org/TR/activitypub/#security-considerations), on the security considerations section at B.3, access to Localhost services should be prevented while running in production.

Recommendation

Update the webfinger.js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
webfinger.js
Anything's wrong? Let us know Last updated on August 01, 2025

This issue is available in SmartScanner Professional

See Pricing