🚨 HIGH Severity Vulnerability: Package unsafe for use as of v1.1.8 🚨
Open
- Dominant language
- JavaScript
- Stars
- 1.5k
- Forks
- 228
- PR merge metrics
- No merged PRs in 30d
Description
**Until PR is merge to mitigate this attack vector, package should be deemed unsafe for use.**
NPM IP package vulnerable to Server-Side Request Forgery (SSRF) attacks, see [GitHub advisory](https://github.com/advisories/GHSA-78xj-cgh5-2h22) for more information.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reading the linked GitHub advisory, then identify the affected package behavior and the mitigation expected for the SSRF attack vector. No files, tests, or entry points are named in the issue; done means the vulnerability is mitigated and the package is no longer unsafe for use.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, node.js
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100