HIGH
OP-Engineering
CVE published 2026-08-20
CVE-2026-61704
CVE-2026-61704 is a high-severity vulnerability in Link Preview JS, a library used to extract web link information. The vulnerability, which has a CVSS score of 7.5, allows an attacker-controlled DNS server to bypass the SSRF protection and cause the server-side preview fetch to reach internal HTTP resources. This is achieved through a DNS rebinding condition, where the resolveDNSHost mitigation in index. [truncated]