mirror of
https://github.com/mauriceboe/TREK.git
synced 2026-06-19 13:21:46 +00:00
33d8953554
- Replace substring check with strict hostname validation (goo.gl, maps.app.goo.gl) - Add checkSsrf() guard with bypass=true to block private/internal IPs unconditionally - Prevents crafted URLs like https://evil.com/?foo=goo.gl from triggering server-side fetches