CVE-2026-43897

HIGH

Link Preview JS: vunerable to IPv6 and internal loopback attacks

Title source: cna
STIX 2.1

Description

Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. There was also a DNS attack, where an address could be resolved into an internal IP. This could cause internal data leaks. This vulnerability is fixed in 4.0.1.

Scores

CVSS v4 8.7
EPSS 0.0005
EPSS Percentile 16.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
npm/link-preview-js 0 - 4.0.1npm
OP-Engineering/link-preview-js < 4.0.1
Published May 11, 2026
Tracked Since May 12, 2026