The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2024-29415.Referenceshttps://cosmosofcyberspace.github.io/CVE-Application-Document.htmlhttps://github.com/indutny/node-ip/issues/160