CVE-2025-2691: nossrf Server-Side Request Forgery (SSRF)
8.2
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.13346%
CWE
Published
3/23/2025
Updated
3/25/2025
KEV Status
No
Technology
JavaScript
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| nossrf | npm |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability manifests in URL validation logic that checks hostnames without proper verification of their resolved IP addresses. The PoC explicitly shows the asyncValidateUrl function returning true for a hostname resolving to 127.0.0.1, indicating this function contains the flawed validation logic. As this is the primary SSRF protection function mentioned in documentation and PoC, and the CVE describes bypassing protection mechanisms, this function is clearly implicated.