Junglewise Threat Intelligence

Karakeep SDK SSRF in metascraper-logo-favicon bypasses validateUrl

Severity: medium · CVSS 4 · Published 2026-05-14

Vendors: npm.

Executive brief

Karakeep is a web-based bookmark manager. When users create bookmarks, the application extracts favicon URLs from the bookmarked pages' HTML. A security flaw allows attackers to craft malicious favicon links that bypass the application's SSRF protections, enabling access to cloud metadata endpoints, internal services, and private network resources—potentially exposing credentials and sensitive internal data.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) in the metascraper-logo-favicon plugin (v5.49.5) used during HTML parsing. The application correctly validates the primary bookmark URL via validateUrl(), which blocks private/loopback IPs and resolves DNS before connecting. However, favicon URLs extracted from HTML link tags are fetched via the reachable-url library without passing through validateUrl(), allowing direct requests to internal IPs (127.0.0.1, 169.254.169.254, 192.168.x.x). An authenticated attacker can create a bookmark pointing to a public attacker-controlled page containing malicious favicon href attributes targeting internal services. When processed, the server makes unvalidated HTTP GET requests to those internal URLs, potentially exposing IAM credentials, internal service discovery, and sensitive data. A fix is available in version 0.32.0 and later.

Affected products

  • Karakeep SDK <= 0.31.0

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: patched: Patched in version 0.32.0

References

Related threats