← Back to CVE List

CVE-2025-27152

Published: 2025-03-07T16:15Z
Last Modified: 2025-03-07T20:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ?baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt