Description
All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF), where an attacker can provide an IP or hostname that resolves to a multicast IP address (224.0.0.0/4) which is not included as part of the private IP ranges in the package’s source code.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.0.2
References
Could your website be exposed too?
SmartScanner can check your website for private-ip vulnerable to Server-Side Request Forgery and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module - CVE-2025-62505
- Server-Side Request Forgery in private-ip - CVE-2020-28360
- Axios vulnerable to Server-Side Request Forgery - CVE-2020-28168
- Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter - CVE-2025-58179


