Skip to content

axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL #486

@AntonioVentilii

Description

@AntonioVentilii

Hi,

This is similar to what peterpeterparker reported in August 2024 with #443 .

I'm opening this issue to point out that npm audit is currently reporting a vulnerability with the alchemy-sdk-js, which is related to the inherited dependency axios. It would be great if you could bump the version to fix the security warning.

axios <1.8.2
Severity: high
axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL - GHSA-jr5f-v2jv-69x6
fix available via npm audit fix
node_modules/axios

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions