Repository navigation
fix(security): fix security issue in axios via minor version upgrade from 1.13.4 to 1.20.0 - #174
Open
aikido-autofix[bot] wants to merge 1 commit into
Open
aikido-autofix[bot] wants to merge 1 commit into
aikido-autofix[bot] wants to merge 1 commit into
Conversation
✅ Security Analysis ResultsNo security issues found. 2 files reviewed.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary / Description
Upgrade axios to fix critical security vulnerabilities including proxy bypass/SSRF via hostname normalization, prototype pollution header injection, credential leakage on cross-origin redirects, and HTTPS proxy cleartext exposure.
Security Impact — CVE vulnerabilities fixed by this PR
✅ 12 CVEs resolved by this upgrade
This PR will resolve the following CVEs:
X-API-Key) during cross-origin redirects, potentially leaking API keys and authentication tokens to unintended hosts. This information disclosure vulnerability affects shared environments where secret headers are set by default.//(e.g.,https:internal.example), allowing attackers to bypass URL allowlists or WAF checks and reach unintended hosts. The vulnerability enables URL validation bypass through silent normalization of invalid URLs.formDataToJSONhelper allows attackers to polluteObject.prototypethrough specially crafted multipart field names, potentially enabling remote code execution or other malicious actions.Breaking Changes & Upgrade Impact — prefer Warnings / Cautions /⚠️ sections over implementation sections (upgrade risks, breaking changes, manual migration steps)
✅ Code not affected by breaking changes.
✅ After thoroughly searching the codebase for usages of the features affected by the axios upgrade breaking changes, I found no code that would be impacted:
Header Injection (CRLF): No code dynamically constructs headers with
\ror\ncharacters. All headers are static (e.g.,'Content-Type': 'application/json',Accept: 'application/json') or use theAuthorizationheader with bearer tokens.Fetch adapter with
maxBodyLength/maxContentLength: The codebase does not configure or use the fetch adapter, nor does it setmaxBodyLengthormaxContentLengthlimits anywhere.parseProtocolchanges: The codebase does not use theparseProtocolfunction directly.Deprecated
unescape()replacement: The codebase does not use theunescape()function. URL encoding is handled viaencodeURIComponent()inbuildUrlWithParams().Malformed URLs without
//: All URLs in the codebase use proper format with//(e.g.,https://api.typeform.com,http://test.com,http://typeform.com). The URL construction inbuildUrlWithParams()andcreate-client.tsconcatenates properly formatted base URLs with paths.The upgrade from axios 1.13.4 to 1.18.0 should not cause any breaking changes for this codebase.
All breaking changes by upgrading axios from version 1.13.4 to 1.20.0 (CHANGELOG)
\ror\ncharacters now throw"Invalid character in header content"instead of being accepted.maxBodyLengthandmaxContentLengthlimits that were previously silently ignored.parseProtocolnow strictly requires a colon in the protocol separator; strings that loosely parsed as protocols before may no longer match.unescape()replaced with modern UTF-8 encoding; non-ASCII URL handling is now spec-correct and consumers depending on legacyunescape()quirks may see different output bytes.http:andhttps:URLs that omit//are now rejected withERR_INVALID_URL.ContentTooLarge(413) andUnprocessableContent(422), while retainingPayloadTooLargeandUnprocessableEntityas backward-compatible deprecated aliases.Fix Details / Technical Implementation (detailed write-up of what was changed and why)
🤖 Remediation details
Fix axios security vulnerabilities (multiple HIGH/MEDIUM/LOW CVEs)
Short summary
This PR remediates multiple security vulnerabilities in axios by bumping its declared version floor in the root
package.json. Theaxiospackage is a direct runtime dependency of this project; the fix updates both the manifest range and the resolved entry inyarn.lock.axios
axioswas declared as a direct dependency at^1.13.4, resolving to1.13.4, which falls within multiple vulnerable ranges covering a series of HIGH, MEDIUM, and LOW severity advisories. The declared range inpackage.jsonwas raised to^1.18.0, andyarn install --ignore-engines --ignore-scriptswas run to refreshyarn.lock, which resolvedaxiosto1.20.0. No parent-chain analysis orresolutionsoverride was required becauseaxiosis a direct dependency and the new range is semver-compatible with the existing^specifier.Version changes
^1.13.4(resolved1.13.4)^1.18.0(resolved1.20.0)