{"id":"GHSA-q4x5-8cj6-52wg","summary":"Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP","details":"Summary:\nThe private IP blocklist regex used in the URL download feature does not match IPv4-mapped IPv6 addresses (e.g. ::ffff:127.0.0.1), allowing SSRF protection to be bypassed on dual-stack systems.\n\nAffected components\n\nbackend/src/applications/files/services/files-manager.service.ts – downloadFromUrl() checks regExpPrivateIP against request.socket.remoteAddress.\nbackend/src/applications/files/utils/url-file.ts – regExpPrivateIP does not include ::ffff:\u003cipv4\u003e variants.\n\nDetails:\nThe regExpPrivateIP regex in backend/src/applications/files/utils/url-file.ts correctly blocks standard IPv4 private ranges but does not include ::ffff: prefixed variants. On dual-stack systems, Node.js can report a socket's remoteAddress in IPv4-mapped IPv6 form, meaning the check in FilesManager.downloadFromUrl() can be bypassed entirely.\n\nPoC:\n[poc.pdf](https://github.com/user-attachments/files/26990874/poc.pdf)\n\n\n\n\nProof:\n\u003cimg width=\"1080\" height=\"842\" alt=\"1000226655\" src=\"https://github.com/user-attachments/assets/797cea83-0a08-4a16-a91b-31c51068d473\" /\u003e\n\n\n\n\n\nImpact:\nAn attacker can supply a crafted URL pointing to an internal address that gets reported as ::ffff:127.0.0.1 or ::ffff:10.x.x.x, causing the server to fetch internal resources that should be blocked. Any user with access to the file download feature is a potential attacker.","aliases":["CVE-2026-47684"],"modified":"2026-07-08T17:45:18.193904281Z","published":"2026-06-05T16:34:59Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-05T16:34:59Z","nvd_published_at":"2026-06-16T15:16:41Z","cwe_ids":["CWE-918"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/Sync-in/server/security/advisories/GHSA-q4x5-8cj6-52wg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47684"},{"type":"PACKAGE","url":"https://github.com/Sync-in/server"},{"type":"WEB","url":"https://github.com/Sync-in/server/releases/tag/v2.3.0"}],"affected":[{"package":{"name":"@sync-in/server","ecosystem":"npm","purl":"pkg:npm/%40sync-in/server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.3.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.2.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-q4x5-8cj6-52wg/GHSA-q4x5-8cj6-52wg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}