Cross-site request forgery in TerriaJS-Server - CVE-2026-77628
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform unauthorized state-changing actions.
The vulnerability exists due to missing cross-site request forgery protection in the /share, /feedback, and /esri-token-auth endpoints when processing cross-origin browser requests. A remote attacker can cause the victim's browser to send crafted cross-origin requests to perform unauthorized state-changing actions.
Exploitation requires the victim to visit an attacker-controlled web page and a deployment that authenticates by network position or ambient authority. Responses cannot be read cross-origin.