WhisperX tag archive

#CVE-2023-28155

This page collects WhisperX intelligence signals tagged #CVE-2023-28155. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-21 10:22:42 · GitHub Issues

1. Deprecated 'request' npm Package Exposes Projects to SSRF via CVE-2023-28155, No Fix Available

A critical dependency alert reveals that the widely used but deprecated `request` npm library contains an unfixed Server-Side Request Forgery (SSRF) vulnerability, CVE-2023-28155. The flaw, rated medium severity, allows attackers to exploit the library's handling of cross-protocol redirects—such as from HTTP to `file:/...