MEDIUM 5.9 npm

Axios vulnerable to Server-Side Request Forgery

GHSA-4w2v-q235-vp99 · CVE-2020-28168

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

Ready to move

Start Securing

Free, no credit card | First findings in minutes