-
-
Notifications
You must be signed in to change notification settings - Fork 186
Closed
Description
What
Axios has a new security issue identified: CVE-2025-27152.
If a baseurl is set, Axios will incorrectly send a request to a different server if provided an absolute URL containing a different server. This exposes a risk of Server Side Request Forgery or Credential Leakage.
Why fix
Although unlikely to be directly exploitable here, by requiring a patched version of Axios as a dependency, this will assist / encourage / force end users into using a patched version of Axios.
Lots of extra info here (covering both the previous CVE and this one): axios/axios#6463
How to fix
Just update the dependency on Axios to version 1.8.2 or greater. I'll add a pull request for this.
Ciock, jarodsmk, bastienmoulia, avaslev, blimmer and 3 more
Metadata
Metadata
Assignees
Labels
No labels