VDB
KO
HIGH

GHSA-8hc4-vh64-cxmj

Server-Side Request Forgery in axios

Details

axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / axios
Introduced in: 1.3.2 Fixed in: 1.7.4
Fix npm install axios@1.7.4

References