Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more
- Category
- Supply Chain
- Confidence
- 93% confidence
- Finding
The lockfile pins axios 1.13.6, and the provided advisory set includes multiple high-severity issues affecting request handling, proxy logic, and prototype-pollution-related attack chains. In a skill that appears to automate affiliate marketing and likely performs outbound HTTP requests and scraping, a vulnerable HTTP client materially increases risk of SSRF, credential leakage, request tampering, or response hijacking when processing attacker-influenced URLs or proxy settings.
- Content
