CVE-2021-28918 is a critical improper input validation vulnerability in the netmask npm package (v1.0.6 and below), affecting numerous dependent packages. This flaw allows unauthenticated remote attackers to bypass IP filtering, leading to Server-Side Request Forgery (SSRF), Remote File Inclusion (RFI), and Local File Inclusion (LFI attacks, potentially reaching critical internal hosts. With a CVSS score of 9.1 (CRITICAL) and an EPSS score indicating high exploitability, the vulnerability is easily exploitable over the network with low attack complexity, resulting in high confidentiality and integrity impacts. While not listed in CISA's KEV catalog, Nuclei templates exist for SSRF exploitation, and the vulnerability has garnered significant community discussion and media coverage, indicating widespread awareness and potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.6CPE matchmatch criteria | cpe:2.3:a:netmask_project:netmask:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.