Vulnerabilities/

Server-Side Request Forgery in link-preview-js

Severity:
Medium

Description

The package link-preview-js before 2.1.17 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.

Recommendation

Update the link-preview-js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
link-preview-js
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing