CVE-2025-27152
Even if baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.
- CVSS 4.0
- 7.7 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- axios/axios
- Source
- security-advisories@github.com
References
- https://github.com/axios/axios/issues/6463Broken Link
- https://github.com/axios/axios/security/advisories/GHSA-jr5f-v2jv-69x6Exploit, Vendor Advisory
- https://github.com/axios/axios/security/advisories/GHSA-jr5f-v2jv-69x6Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.