owasp-top-10
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyreferences/ssrf.md
LOWAnomalyLOW
references/ssrf.md
The fragment documents SSRF and includes an intentionally vulnerable example where user input reaches fetch() without validation. The secure example demonstrates an allow-list mitigation but is not comprehensive against all SSRF bypasses. It contains no evidence of supply-chain malware or malicious intent; the primary security concern is the explicitly shown vulnerable pattern if copied into an application.
Confidence: 99%Severity: 62%
Audit Metadata