VDB
Sign up
HIGH

GHSA-8hc4-vh64-cxmj

Server-Side Request Forgery in axios

Quick fix

GHSA-8hc4-vh64-cxmj — axios: upgrade to the fixed version with the command below.

npm install axios@1.7.4

Details

axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/axios
Introduced in: 1.3.2Fixed in: 1.7.4
Fixnpm install axios@1.7.4

References