CVE-2025-27152 | axios up to 1.8.1 URL server-side request forgery (Nessus ID 234362 / WID-SEC-2025-0998)
A vulnerability was found in axios up to 1.8.1. It has been rated as critical. This affects an unknown part of the component URL Handler. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2025-27152. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.