Vulnerabilities/

evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API

Severity:
Medium

Description

A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate an HTTP request via the “GET /images” API.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@evershop/evershop
Anything's wrong? Let us know Last updated on January 05, 2026