Description
All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF), where an attacker can provide an IP or hostname that resolves to a multicast IP address (224.0.0.0/4) which is not included as part of the private IP ranges in the package’s source code.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.0.2
References
Related Issues
- Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module - CVE-2025-62505
- Server-Side Request Forgery in private-ip - CVE-2020-28360
- Axios vulnerable to Server-Side Request Forgery - CVE-2020-28168
- Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter - CVE-2025-58179
You might also like:
- Tags:
- npm
- private-ip
Anything's wrong? Let us know Last updated on September 25, 2025


