ssrf

Warn

Audited by Socket on May 12, 2026

1 alert found:

Security
SecurityMEDIUM
references/poc-skeleton.md

This file is an explicit SSRF exploitation PoC template intended to coerce a server-side URL fetch using an attacker-controlled `url` value. The included payloads specifically target cloud instance metadata services and provide multiple validation-bypass encodings and redirect-based strategies, which are commonly used to obtain temporary credentials and sensitive metadata. While the snippet itself only performs a POST and prints the response, its purpose and embedded payload guidance make it high-risk if shipped or executed in a larger system, especially if it is used against any SSRF-capable endpoint.

Confidence: 76%Severity: 82%
Audit Metadata
Analyzed At
May 12, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/ByamB4%2Ffind-cve-agent%2Fssrf%2F@9723c8e8a49163989003f518748cbaba7dad3da8
Security Audit — socket — ssrf