Intel

AIKIDO-2025-10322

@boxyhq/internal-ui is vulnerable to Server-side Request Forgery (SSRF)

Server-side Request Forgery (SSRF) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 23, 2025

62

Medium Risk

This Affects:

JS@boxyhq/internal-ui
0.0.1 - 1.44.0
Fixed in 1.45.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to server-side request forgery (SSRF) due to insufficient validation in the validateMetadataURL method, which fails to check whether user-supplied URLs resolve to private or internal IP addresses. This oversight allows attackers to craft URLs targeting internal services or cloud metadata endpoints.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@boxyhq/internal-ui is vulnerable to Server-side Request Forgery (SSRF) in versions 0.0.1 - 1.44.0.

How to fix this

Upgrade the @boxyhq/internal-ui library to a patch version.