Server-Side Request Forgery in node-ip Package from NPM
CVE-2025-59436

3.2LOW

Key Information:

Status
Vendor
CVE Published:
16 September 2025

What is CVE-2025-59436?

The node-ip package, utilized within various applications through NPM, contains a vulnerability that may allow an attacker to exploit server-side request forgery (SSRF) due to an improper classification of the IP address value 017700000001 as globally routable. This misclassification arises from an incomplete fix related to a previous security issue. As a result, developers and users must be vigilant about the versions they deploy and the potential exposure of their applications to SSRF attacks.

Affected Version(s)

ip 0 <= 2.0.1

References

CVSS V3.1

Score:
3.2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59436 : Server-Side Request Forgery in node-ip Package from NPM