Known Vulnerable Dependency: axios==1.14.0 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more
- Category
- Supply Chain
- Confidence
- 97% confidence
- Finding
The lockfile pins axios 1.14.0, and the supplied advisories indicate multiple known issues including SSRF/proxy bypass and prototype-pollution-related request/credential compromise paths. For a skill whose purpose is to query internal available AI models, outbound HTTP requests are central to its function, so vulnerable HTTP client behavior materially increases risk to internal services, credentials, and response integrity.
- Content
