Skip to content

PMK-1997: Update Vulnerable Axios Dependency#175

Open
MattReibach wants to merge 3 commits intomainfrom
pmk-1997-update-vulnerable-axios-dependency
Open

PMK-1997: Update Vulnerable Axios Dependency#175
MattReibach wants to merge 3 commits intomainfrom
pmk-1997-update-vulnerable-axios-dependency

Conversation

@MattReibach
Copy link

@MattReibach MattReibach commented Feb 3, 2026

Update Axios version (current ^1.7.4) to latest ^1.13.4 to resolve High severity vulnerability.

Dependabot Alert: https://github.com/ActiveCampaign/postmark.js/security/dependabot/41

Snyk Report:

Upgrade axios@1.7.4 to axios@1.12.0 to fix
  ✗ Allocation of Resources Without Limits or Throttling [Medium Severity][https://security.snyk.io/vuln/SNYK-JS-AXIOS-12613773] in axios@1.7.4
    introduced by axios@1.7.4
  ✗ Server-side Request Forgery (SSRF) [Medium Severity][https://security.snyk.io/vuln/SNYK-JS-AXIOS-9403194] in axios@1.7.4
    introduced by axios@1.7.4
  ✗ Server-side Request Forgery (SSRF) [Medium Severity][https://security.snyk.io/vuln/SNYK-JS-AXIOS-9292519] in axios@1.7.4
    introduced by axios@1.7.4

Copy link
Contributor

@dandigangi dandigangi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link

@J0SUEFDZ J0SUEFDZ left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants