HIGH7.4
GHSA-663h-2vr3-ghrj
yapi disables TLS/SSL certificate validation via rejectUnauthorized: false in Axios HTTPS agent
Details
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/yapi-vendor
Introduced in:
0No fixed version published yet for yapi-vendor (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-70058[ADVISORY]
- https://gist.github.com/zcxlighthouse/11c53803faf23f607c2787c166e811d4[WEB]
- https://github.com/YMFE[WEB]
- https://github.com/YMFE/yapi[PACKAGE]
- https://github.com/YMFE/yapi/blob/59bade3a8a43e7db077d38a4b0c7c584f30ddf8c/common/postmanLib.js#L110[WEB]