indutny / indutny/node-ip

🚨 HIGH Severity Vulnerability: Package unsafe for use as of v1.1.8 🚨

Open
#136 26 comments 105 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
1.5k
Forks
228
PR merge metrics
No merged PRs in 30d

Description

**Until PR is merge to mitigate this attack vector, package should be deemed unsafe for use.**

NPM IP package vulnerable to Server-Side Request Forgery (SSRF) attacks, see [GitHub advisory](https://github.com/advisories/GHSA-78xj-cgh5-2h22) for more information.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading the linked GitHub advisory, then identify the affected package behavior and the mitigation expected for the SSRF attack vector. No files, tests, or entry points are named in the issue; done means the vulnerability is mitigated and the package is no longer unsafe for use.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, node.js
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.