media-use
Warn
Audited by Socket on Oct 5, 2026
1 alert found:
AnomalyAnomalyscripts/lib/media-fetch.mjs
LOWAnomalyLOW
scripts/lib/media-fetch.mjs
The code implements useful protocol, redirect, and response-size checks, but its public-host validation does not verify DNS resolution or the actual connected address. Consequently, a hostname resolving to an internal address can bypass the SSRF protection. No evidence of intentional malicious behavior is present.
Confidence: 96%Severity: 55%
Audit Metadata