DNS Rebinding Vulnerability in Link Preview JS by OP Engineering
CVE-2026-61704
7.5HIGH
What is CVE-2026-61704?
Link Preview JS prior to version 4.0.4 contains a vulnerability related to DNS rebinding through the resolveDNSHost function. This flaw allows an attacker-controlled DNS server to send a public IP address during the validation process, while later redirecting to a loopback or internal IP address during actual connection attempts. This bypasses the server-side request forgery (SSRF) protections, enabling unauthorized access to internal HTTP resources. The issue has been addressed in version 4.0.4, mitigating the risk of such exploits.
Affected Version(s)
link-preview-js < 4.0.4
