PT-2026-99950 · Npm · Axios
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Axios versions 1.17.0 through 1.19.x
Description
The fetch adapter bypasses the
maxRedirects: 0 redirect policy. When a request is configured with maxRedirects set to zero and receives a redirect response, the underlying fetch implementation follows the redirect instead of returning the response unchanged. This behavior allows redirected requests to access internal responses or reach state-changing internal endpoints even when redirects are disabled.Recommendations
Update to version 1.20.0.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Axios