PT-2026-79062 · Npm · Link-Preview-Js

CVE-2026-61704

·

Published

2026-08-20

·

Updated

2026-09-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Link Preview JS versions prior to 4.0.4
Description A DNS rebinding condition exists in the resolveDNSHost mitigation within index.ts. The system validates a single resolved IP address but subsequently fetches the original hostname. This allows a malicious DNS server to provide a public address during the validation phase and a loopback or internal address during the actual connection, bypassing Server-Side Request Forgery (SSRF) protections. Consequently, the server-side preview fetch can access internal HTTP resources. This mismatch between validation and fetching also affects redirect handling.
Recommendations Update to version 4.0.4.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61704
GHSA-CPJF-6666-R8FX

Affected Products

Link-Preview-Js