- Description
- axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- axios
CVSS 4.0
- Type
- Secondary
- Base score
- 7.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
- security-advisories@github.com
- CWE-918
- Hype score
- Not currently trending
NEW THREAT INTEL: Storm-2755 Payroll Pirate - AiTM phishing hijacks Canadian M365 sessions, replays tokens via Axios 1.7.9 (CVE-2025-27152), reroutes Workday direct deposits. 9 detections, 18 IOCs. https://t.co/qDaPAKTE8Q #ThreatIntel #AiTM #Workday https://t.co/l2tKtALzVQ
@threadlinqs
10 Apr 2026
208 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
Today I ran into two critical vulnerabilities CVE-2025-27152 & CVE-2025-58754 To be safe, I run automation scripts every single day to check for zero day vulnerabilities & manually check all production servers before starting any process. As a developer and a pentester
@nyuiela
13 Dec 2025
43 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Axios JavaScript Library の深刻な脆弱性 CVE-2025-27152 が FIX:SSRF と PoC エクスプロイト https://t.co/jCNvUoFH8h Axios JavaScript Library に脆弱性が発生しています。このライブラリは月に2億以上のダウンロードを誇るとのことなので、脆弱性の影響範囲はかなり広範になります。さらに、PoC… https://t.co/91LZX31YYa
@iototsecnews
19 Mar 2025
62 Impressions
2 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Follow @zoomeye_team & Get 7-Day Membership! 🚨🚨A wild vuln just dropped: CVE-2025-27152 in Axios! This sneaky flaw could let attackers pull off some slick SSRF moves or snag creds via absolute URLs. MILLIONS of users might be exposed! 🔥PoC: https://t.co/yJ24tTpDcw Zoom
@zoomeye_team
13 Mar 2025
334 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
JavaScriptの人気ライブラリAxiosで重大な脆弱性(CVE-2025-27152)|セキュリティニュース 提供元: 合同会社ロケットボーイズ https://t.co/SfTinxuj1u
@Neptunetx2
13 Mar 2025
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
RT @Dinosn: Popular JavaScript Library ‘Axios’ Exposes Millions to Server-Side Vulnerabilities (CVE-2025-27152)
@ArielSimmo92815
12 Mar 2025
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨Alert🚨 CVE-2025-27152:Possible SSRF and Credential Leakage via Absolute URL in axios Requests 🔥PoC:https://t.co/METzB4xHYv 📊 202K+ Services are found on the https://t.co/ysWb28Crld yearly. 🔗Hunter Link:https://t.co/2Jz1DeTGt2 👇Query HUNTER :… https://t.co/uZIjwBUIFl https:
@HunterMapping
12 Mar 2025
3596 Impressions
13 Retweets
70 Likes
34 Bookmarks
1 Reply
0 Quotes
CVE-2025-27152: JavaScript Library ‘Axios’ Exposes Millions to Server-Side Vulnerabilities. https://t.co/GkZ7FRrYOv https://t.co/JsrrS7Hajj
@cyber_advising
12 Mar 2025
1143 Impressions
1 Retweet
15 Likes
7 Bookmarks
0 Replies
0 Quotes
Threat Alert: Popular JavaScript Library 'Axios' Exposes Millions to Server-Side Vulnerabiliti CVE-2025-27152 Severity: ⚠️ Critical Maturity: 💢 Emerging Learn more: https://t.co/fENHrcWh1s #CyberSecurity #ThreatIntel #InfoSec
@fletch_ai
12 Mar 2025
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JavaScriptの人気ライブラリ Axios(アクシオス)で重大な脆弱性(CVE-2025-27152)が発生しています。 公式からPoCも一部公開されているので対象者はアップデートする事をお勧めします。 #セキュリティ対策Lab #セキュリティ #Security https://t.co/adlgWkG3L0
@securityLab_jp
12 Mar 2025
21 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
Popular JavaScript Library ‘Axios’ Exposes Millions to Server-Side Vulnerabilities (CVE-2025-27152) https://t.co/pj8ylJ75JI
@Dinosn
11 Mar 2025
98121 Impressions
34 Retweets
213 Likes
76 Bookmarks
1 Reply
8 Quotes
🚨 Lambda Watchdog detected a new HIGH severity CVE 🚨 CVE-2025-27152 was detected in the latest AWS Lambda image scan affecting the axios package in 4 images. Check the full report 👉 https://t.co/6EUGaPyRZk #AWS #Lambda #CVE #CloudSecurity #Serverless
@LambdaWatchdog
8 Mar 2025
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-27152 axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ba… https://t.co/jZLvGBac0k
@CVEnew
8 Mar 2025
89 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "22E658DD-EA2E-454A-BEB1-3B9BC30D017E",
"versionEndExcluding": "0.30.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "2EFCE157-4712-4CC5-8DB4-9ACCC8C1016E",
"versionEndIncluding": "1.7.9",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]