This is a patch bypass of CVE-2025-58179 in commit 9ecf359. The fix blocks http://, https:// and //, but can be bypassed using backslashes (\) - the endpoint still issues a server-side fetch.
{
"nvd_published_at": "2025-10-28T20:15:49Z",
"cwe_ids": [
"CWE-79",
"CWE-918"
],
"github_reviewed_at": "2025-10-28T17:45:04Z",
"severity": "HIGH",
"github_reviewed": true
}