Files
CVEs-PoC/2025/CVE-2025-8020.md
T
2025-09-29 21:09:30 +02:00

869 B

CVE-2025-8020

Description

All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide an IP or hostname that resolves to a multicast IP address (224.0.0.0/4) which is not included as part of the private IP ranges in the package's source code.

POC

Reference

Github

No PoCs found on GitHub currently.