npm package report

Is @papra/webhooks safe?

1 known vulnerability, worst severity LOW.

cvss
3.5

how bad it is if exploited, out of 10

epss
0.20%

chance of exploitation in the next 30 days

xyz score
1.1

CyberXYZ composite, out of 10

fig. 01 — GHSA-5g86-85rp-f9hx, the advisory selected below

// advisories

GHSA-5g86-85rp-f9hx

LOWCVE-2026-48051

Papra's webhook delivery system contains an SSRF protection bypass that allows any authenticated organisation member to cause the server to make HTTP requests to internal addresses — loopback, link-local, and RFC-1918 ranges. The SSRF protection validates the registered webhook URL but ignores redirect destinations. The HTTP client (ofetch) follows 3xx responses automatically, and the redirect tar

Affected
>=0, <0.3.3, < 0.3.3
Fixed in
0.3.3
Weakness
CWE-918
Published
2026-06-10
Source
osv

NVDMITREOSV


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 02:41 UTC. The most recent advisory here was published 2026-06-10. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @papra/webhooks safe? npm package security report | CyberXYZ