Vulnerabilities/

Server-Side Request Forgery in private-ip

Severity:
High

Description

Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF.

Recommendation

Update the private-ip package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
private-ip
Anything's wrong? Let us know Last updated on February 01, 2023