gitnexus is vulnerable to Server-Side Request Forgery (SSRF)
68
Medium Risk
Affected versions of this package contain an SSRF protection bypass in git URL validation, where the IPv6 loopback check failed because the parser normalized [::1] to ::1, and multiple private or special-use IP ranges were not blocked. An attacker could exploit this by supplying a crafted git URL that resolves to localhost, internal network addresses, cloud metadata endpoints, or numerically encoded IPs, potentially forcing the application to make unintended internal requests and exposing sensitive services or credentials.
You are affected if you are using a version that falls within the vulnerable range.
gitnexus is vulnerable to Server-Side Request Forgery (SSRF) in versions 1.0.0 - 1.5.3.
Upgrade the gitnexus library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant