logo

Exploitable Flaw in NPM Private IP App Lurks Everywhere, Anywhere

ID: 60b0fb3f-529c-5183-a2e2-1ddade2e986d

STIX ID: report--60b0fb3f-529c-5183-a2e2-1ddade2e986d

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2020-11-25

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

**Executive summary:** The report describes an SSRF bypass in the widely used npm package private-ip (CVE-2020-28360) where regex-based filtering allowed encoded or obfuscated private IPv4 addresses (hex, zero-padded octets, etc.) to be treated as public, potentially enabling attackers to reach internal resources; the flaw had broad downstream impact across many packages and projects, and a fix implementing proper netmask/byte-level handling was released—organizations using private-ip v1.0.5 or earlier should upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.