Description
Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. There was also a DNS attack, where an address could be resolved into an internal IP. This could cause internal data leaks. This vulnerability is fixed in 4.0.1.
Problem types
CWE-918: Server-Side Request Forgery (SSRF)
Product status
References
github.com/...iew-js/security/advisories/GHSA-4gp8-rjrq-ch6q
github.com/OP-Engineering/link-preview-js/pull/179
github.com/...ommit/4396d48909fab37553c0e93e26447fe218363ede
github.com/OP-Engineering/link-preview-js/releases/tag/4.0.1