Known Vulnerable Dependency: axios==1.13.4 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more
High
- Category
- Supply Chain
- Confidence
- 95% confidence
- Finding
- The lockfile pins axios 1.13.4, and the supplied advisories include multiple high-severity issues affecting request handling, including SSRF/proxy-bypass and prototype-pollution-related attack paths. In a skill that retrieves YouTube data over HTTP, a vulnerable HTTP client is security-relevant because attacker-controlled URLs, redirects, proxy settings, or polluted objects could alter outbound requests, leak credentials, or enable response tampering.
