The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2022-07-01T20:00:22.396158Z

Updated: 2024-09-17T01:56:48.134Z

Reserved: 2022-02-24T00:00:00

Link: CVE-2022-25876

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-07-01T20:15:07.917

Modified: 2022-07-12T18:51:54.013

Link: CVE-2022-25876

cve-icon Redhat

No data.