Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more
High
- Category
- Supply Chain
- Confidence
- 95% confidence
- Finding
- axios 1.13.6 is a direct dependency and the advisory set includes SSRF, redirect/header handling, and prototype-pollution-related issues. This skill fetches real-time YouBike data and supports user-driven search inputs, so any outbound HTTP logic built on axios increases the chance that a vulnerable request path could be reached, especially if URLs, proxy settings, or redirects are influenced by configuration or upstream responses.
