@boxyhq/internal-ui is vulnerable to Server-side Request Forgery (SSRF)
62
Medium Risk
Affected versions of this package are vulnerable to server-side request forgery (SSRF) due to insufficient validation in the validateMetadataURL method, which fails to check whether user-supplied URLs resolve to private or internal IP addresses. This oversight allows attackers to craft URLs targeting internal services or cloud metadata endpoints.
You are affected if you are using a version that falls within the vulnerable range.
@boxyhq/internal-ui is vulnerable to Server-side Request Forgery (SSRF) in versions 0.0.1 - 1.44.0.
Upgrade the @boxyhq/internal-ui library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant