PT-2026-79062 · Npm · Link-Preview-Js
CVE-2026-61704
·
Published
2026-08-20
·
Updated
2026-09-02
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Link Preview JS versions prior to 4.0.4
Description
A DNS rebinding condition exists in the
resolveDNSHost mitigation within index.ts. The system validates a single resolved IP address but subsequently fetches the original hostname. This allows a malicious DNS server to provide a public address during the validation phase and a loopback or internal address during the actual connection, bypassing Server-Side Request Forgery (SSRF) protections. Consequently, the server-side preview fetch can access internal HTTP resources. This mismatch between validation and fetching also affects redirect handling.Recommendations
Update to version 4.0.4.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Link-Preview-Js