Unknown · Link-Preview-Js · CVE-2022-25876
**Name of the Vulnerable Software and Affected Versions**
link-preview-js versions prior to 2.1.16
**Description**
The issue allows attackers to send arbitrary requests to the local network and read the response due to flawed DNS rebinding protection, enabling Server-side Request Forgery (SSRF) attacks.
**Recommendations**
For versions prior to 2.1.16, update to version 2.1.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the local network to minimize the risk of exploitation.