VDB
Sign up
HIGH8.2

GHSA-j9pj-hx76-92v6

Server-Side Request Forgery in phantomjs-seo

Details

This affects all versions of package phantomjs-seo. It is possible for an attacker to craft a url that will be passed to a PhantomJS instance allowing for an SSRF attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/phantomjs-seo
Introduced in: 0

No fixed version published yet for phantomjs-seo (npm). Pin to a known-safe version or switch to an alternative.

References