SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-25876

The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response.

MEDIUM 5.5EPSS 0.37%

Does this matter?

Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.

Description

The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.37% probability · 30th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
link-preview-js project/link-preview-js
Source
report@snyk.io

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.