Description
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
Remediation
References
https://hackerone.com/reports/786956
Related Vulnerabilities
CVE-2022-2596 Vulnerability in npm package node-fetch
CVE-2023-26480 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livedata-webjar
CVE-2014-3603 Vulnerability in maven package org.opensaml:opensaml
CVE-2023-40014 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts-upgradeable