NPM · JULY 2026 · CONFIRMED

'keep' npm Package SSRF Vulnerability: Critical Threat Confirmed

CVE-2026-65057Severity: CRITICAL

A critical server-side request forgery (SSRF) vulnerability has been confirmed in the 'keep' npm package, tracked as CVE-2026-65057. This vulnerability allows unauthenticated attackers to make the backend issue arbitrary HTTP requests, potentially leading to theft of cloud credentials and internal network reconnaissance.

What happened

The 'keep' npm package contains a vulnerability that permits unauthenticated attackers to exploit a server-side request forgery (SSRF) by sending a crafted JSON payload with a malicious host parameter. This can cause the backend to issue outbound requests to internal services or cloud metadata endpoints. According to the NVD, this vulnerability is rated 9.3 on the CVSS scale, indicating a critical severity level.

To assess your exposure, check if your projects or dependencies include the 'keep' npm package. If so, you are potentially vulnerable. The recommended actions are to pin to a non-vulnerable version of 'keep' or upgrade to a patched version once it becomes available. Additionally, rotate any secrets in affected environments to mitigate the risk of credential theft.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If keep is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats