CVE-2026-61704
Last modified
CVE-2026-61704 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public address during validation and a loopback or internal address during the final connection. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public address during validation and a loopback or internal address during the final connection. This DNS rebinding condition bypasses the SSRF protection and can cause the server-side preview fetch to reach internal HTTP resources. Redirect handling is affected by the same validation-to-fetch mismatch. This issue is fixed in version 4.0.4.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| OP-Engineering | link-preview-js | < 4.0.4 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-61704?
How severe is CVE-2026-61704?
How do I fix CVE-2026-61704?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6169The affiliate-toolkit plugin for WordPress is vulnerable to …7.2
- CVE-2026-61690Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipA…6.5
- CVE-2026-61692Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-61696Forem is open source software for building communities. In v…6.3
- CVE-2026-61699nebula-mesh is a self-hosted control plane for Slack Nebula …8.1
- CVE-2026-61701Laravel MagicLink creates links for authentication without a…8.8
- CVE-2026-61710Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-61711BuildKit is a toolkit for converting source code to build ar…5.3
- CVE-2026-61712BuildKit is a toolkit for converting source code to build ar…2.3
- CVE-2026-61718bunkerweb is an Open-source and next-generation Web Applicat…5.4
- CVE-2026-61736LightRAG provides simple and fast retrieval-augmented genera…9.3
- CVE-2026-6174The CC Child Pages plugin for WordPress is vulnerable to Sto…6.4
Are you affected by CVE-2026-61704?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
