Skip to content

Upgrade axios@1.16.0#577

Open
vincent-tock wants to merge 1 commit into
Iterable:mainfrom
vincent-tock:vincent/upgrade-axios
Open

Upgrade axios@1.16.0#577
vincent-tock wants to merge 1 commit into
Iterable:mainfrom
vincent-tock:vincent/upgrade-axios

Conversation

@vincent-tock
Copy link
Copy Markdown

@vincent-tock vincent-tock commented May 18, 2026

Description

We're trying to adopt iterable-web-sdk at my company, Squarespace, however this will not pass our Vulnerability Scan step because this CVE.

New Vulnerable Dependency: axios
---
  Vulnerability: Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
  Severity: high
  Advisory: https://github.com/advisories/GHSA-pmwg-cvhr-8vh7
  Vulnerability in Versions: >=1.0.0 <1.15.1
  Version(s) in lock file: 1.13.4, 1.14.0, 1.7.4, 1.7.7, 1.8.4
  ---
  Vulnerability: Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
  Severity: high
  Advisory: https://github.com/advisories/GHSA-pf86-5x62-jrwf
  Vulnerability in Versions: >=1.0.0 <1.15.1
  Version(s) in lock file: 1.13.4, 1.14.0, 1.7.4, 1.7.7, 1.8.4
  ---
  Vulnerability: Axios: Header Injection via Prototype Pollution
  Severity: high
  Advisory: https://github.com/advisories/GHSA-6chq-wfr3-2hj9
  Vulnerability in Versions: >=1.0.0 <1.15.1
  Version(s) in lock file: 1.13.4, 1.14.0, 1.7.4, 1.7.7, 1.8.4
  ---
  Vulnerability: Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
  Severity: high
  Advisory: https://github.com/advisories/GHSA-q8qp-cvcw-x6jj
  Vulnerability in Versions: >=1.0.0 <1.15.2
  Version(s) in lock file: 1.13.4, 1.14.0, 1.7.4, 1.7.7, 1.8.4
  ---

Test Steps

Ran the test

@vincent-tock vincent-tock requested a review from mprew97 as a code owner May 18, 2026 15:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant