Vulnerabilities/

link-preview-js vulnerable to IPv6 and internal loopback attacks

Severity:
High

Description

The library did not check for IPv6 loopback attacks. There was also a DNS attack, where an address could be resolved into an internal IP. This could cause internal data leaks.

Recommendation

Update the link-preview-js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
link-preview-js
Anything's wrong? Let us know Last updated on May 13, 2026