highVulnerability

GHSA-g2gw-q38m-vjfc

Lokka versions prior to 2.1.2 constructed Azure Resource Manager request URLs using direct string concatenation with user-controlled path input. Specially crafted path values could alter URL authority parsing and cause Azure Resource Manager bearer tokens to be sent to an unintended host. Version 2.1.2 fixes the issue by validating Azure paths before token acquisition and constructing Azure Resource Manager URLs with the standard URL API while preserving the expected management.azure.com host. Reported by 정해창 <[email protected]>

Properties

ghsa_id
GHSA-g2gw-q38m-vjfc
severity
high
summary
Lokka: Azure Resource Manager URL path validation issue
cve_id
GHSA-g2gw-q38m-vjfc
is_ghsa_only
true
ghsa_published
2026-06-19T22:10:39Z
source_url
https://github.com/advisories/GHSA-g2gw-q38m-vjfc
ghsa_updated
2026-06-19T22:10:40Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/@merill/lokka

AFFECTS (1)

[Software]npm/@merill/lokka

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-g2gw-q38m-vjfc — Ninja Signal Threat Intelligence | Ninja Signal