Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Emredurmaz4

#53051of 53,634
3.2Total CVSS
Vulnerabilities · 1
PT-2025-37863
3.2
2025-09-16
Npm · Ip · CVE-2025-59436
**Name of the Vulnerable Software and Affected Versions** ip (aka node-ip) versions through 2.0.1 **Description** The ip (aka node-ip) package may allow Server-Side Request Forgery (SSRF) due to the improper categorization of the IP address value 017700000001 as globally routable via the `isPublic` function. This issue is related to an incomplete fix for a previously identified issue. **Recommendations** Update to a version beyond 2.0.1.