Npm · Ip · CVE-2025-59436
**Name of the Vulnerable Software and Affected Versions**
ip (aka node-ip) versions through 2.0.1
**Description**
The ip (aka node-ip) package may allow Server-Side Request Forgery (SSRF) due to the improper categorization of the IP address value 017700000001 as globally routable via the `isPublic` function. This issue is related to an incomplete fix for a previously identified issue.
**Recommendations**
Update to a version beyond 2.0.1.