Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2023-42282: ip package can let attackers execute code
CVE-2023-42282 · published 2 days ago
Summary
The ip library used in Node.js applications contained a flaw that could let a malicious actor run arbitrary code on your server. Updated versions of the library have been released to fix the problem. Upgrade to the latest version of the ip package from your vendor to protect your system.
What to do
- Update indutny ip to version 2.0.1.
- Update indutny ip to version 1.1.9.
- Update debian node-ip to version 2.0.1+~1.1.3-1.
- Update ip to version 1.1.9-aikido.2.
- Update rootio @rootio/ip to version 1.1.9-root.io.2.
- Update fedorindutny ip to version 1.1.9 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | indutny | ip |
2.0.0 < 1.1.9 Fix: upgrade to 2.0.1
|
| – | fedorindutny | ip |
< 1.1.9 2.0.0 cpe:2.3:a:fedorindutny:ip:*:*:*:*:*:node.js:*:* |
| Debian:12 | debian | node-ip | All versions |
| Debian:13 | debian | node-ip |
< 2.0.1+~1.1.3-1 Fix: upgrade to 2.0.1+~1.1.3-1
|
| Root:npm | – | ip |
< 1.1.9-aikido.2 Fix: upgrade to 1.1.9-aikido.2
|
| Root:npm | rootio | @rootio/ip |
< 1.1.9-root.io.2 Fix: upgrade to 1.1.9-root.io.2
|
Original advisory text
CVE-2023-42282 in ip - Patched by Root
Root has patched CVE-2023-42282 in the ip package for Root:npm. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-42282
- https://cosmosofcyberspace.github.io/npm_ip_cve/npm_ip_cve.html
- https://github.com/JoshGlazebrook/socks/issues/93#issue-2128357447
- https://github.com/github/advisory-database/pull/3504#issuecomment-1937179999
- https://github.com/indutny/node-ip/pull/138
- https://github.com/indutny/node-ip/commit/32f468f1245574785ec080705737a579be1223...
- https://github.com/indutny/node-ip/commit/6a3ada9b471b09d5f0f5be264911ab564bf678...
- https://github.com/advisories/GHSA-78xj-cgh5-2h22
- https://huntr.com/bounties/bfc3b23f-ddc0-4ee7-afab-223b07115ed3/ Exploit Technical Description
- https://security.netapp.com/advisory/ntap-20240315-0008/ Third Party Advisory
- https://www.bleepingcomputer.com/news/security/dev-rejects-cve-severity-makes-hi... Press/Media Coverage
- https://security-tracker.debian.org/tracker/CVE-2023-42282 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-918Server-Side Request Forgery (SSRF)
Timeline
Published30 Sep 2026
Updated30 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta