Server-Side Request Forgery Vulnerability in Private-IP by Snyk
CVE-2025-8020
8.8HIGH
What is CVE-2025-8020?
The private-ip package is susceptible to Server-Side Request Forgery (SSRF) leading to unauthorized access. An attacker can exploit this vulnerability by providing an IP or hostname that resolves to a multicast IP address within the range of 224.0.0.0 to 239.255.255.255, which is not recognized as part of the private IP address ranges in the package's code. This flaw can allow attackers to bypass security controls and communicate with internal services that are otherwise protected.
Affected Version(s)
private-ip 0