Skip to content

Critical vulnerability on Axios & axios-ntlm (fixed on axios >=1.15.0) #1483

@Pankeking

Description

@Pankeking

Hi, thanks for maintaining SOAP!

Our security scan shows soap depends on vulnerable axios versions via soap > axios and soap > axios-ntlm > axios.
The issue is GHSA-fvcv-3m26-pcqx (critical “Unrestricted Cloud Metadata Exfiltration via Header Injection Chain”), fixed in axios >= 1.15.0.

Could you please bump axios and axios-ntlm to >= 1.15.0 when you get a chance?
thank you very much!

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions