CVE-2026-43897 HIGH

CVE-2026-43897: Link Preview JS: vunerable to IPv6 and internal loopback attacks

Vendor Op-Engineering
Product link-preview-js
Weakness CWE-918 · SSRF
Published May 11, 2026
Last update May 12, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. There was also a DNS attack, where an address could be resolved into an internal IP. This could cause internal data leaks. This vulnerability is fixed in 4.0.1.

Key dates

02Disclosure timeline

May 11, 2026 CVE published
May 12, 2026 Record updated