Skip to content

Axios v1.7.9 has a security vulnerability and should be upgraded to latest #2461

@joshmossas

Description

@joshmossas

Dependabot is giving me the following alert for Axios v1.7.9 which is being used by this package.

axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL

The vulnerability was reported originally here axios/axios#6463

The latest version of Axios has a fix that removes this vulnerability.

Proposed Fix

Upgrade to latest version of Axios (v1.8.2)
Alternatively Axios could be replaced as mentioned in #2403 but that would be more involved.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions