media-use

Warn

Audited by Socket on Oct 5, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/lib/media-fetch.mjs

The code implements useful protocol, redirect, and response-size checks, but its public-host validation does not verify DNS resolution or the actual connected address. Consequently, a hostname resolving to an internal address can bypass the SSRF protection. No evidence of intentional malicious behavior is present.

Confidence: 96%Severity: 55%
Audit Metadata
Analyzed At
Oct 5, 2026, 03:15 AM
Package URL
pkg:socket/skills-sh/heygen-com%2Fhyperframes%2Fmedia-use%2F@53c46d6672c0d92e1cba75e044d431889bd6928c8ca0580a9163fa9a5c5ddd35
Security Audit — socket — media-use