Vulnerability Description
axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Axios | Axios | < 0.30.0 |
Related Weaknesses (CWE)
References
- https://github.com/axios/axios/issues/6463Broken Link
- https://github.com/axios/axios/security/advisories/GHSA-jr5f-v2jv-69x6ExploitVendor Advisory
- https://github.com/axios/axios/security/advisories/GHSA-jr5f-v2jv-69x6ExploitVendor Advisory
FAQ
What is CVE-2025-27152?
CVE-2025-27152 is a vulnerability with a CVSS score of 5.3 (MEDIUM). axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if baseURL is set, axios sends the requ...
How severe is CVE-2025-27152?
CVE-2025-27152 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27152?
Check the references section above for vendor advisories and patch information. Affected products include: Axios Axios.