Skip to content

fix: Upgrade axios to fix SSRF vulnerability#11599

Merged
anthonyshew merged 1 commit intomainfrom
fix/axios-ssrf-vulnerability
Jan 31, 2026
Merged

fix: Upgrade axios to fix SSRF vulnerability#11599
anthonyshew merged 1 commit intomainfrom
fix/axios-ssrf-vulnerability

Conversation

@anthonyshew
Copy link
Copy Markdown
Contributor

Summary

  • Upgrades axios from 0.27.2 to 1.9.0 in @turbo/codemod to address a high severity SSRF and credential leakage vulnerability

Details

Vulnerability: SSRF and Credential Leakage in axios <0.30.0
Severity: High
Reference: TURBO-5143

The affected code (packages/turbo-codemod/src/commands/migrate/steps/getLatestVersion.ts) uses axios.get() for simple HTTP requests, which is fully compatible with axios 1.x.

Testing

  • Type checking passes for the affected file
  • No breaking API changes for the simple axios.get() usage pattern

@vercel
Copy link
Copy Markdown
Contributor

vercel Bot commented Jan 31, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
examples-basic-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 8:42pm
examples-designsystem-docs Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 8:42pm
examples-gatsby-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 8:42pm
examples-kitchensink-blog Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 8:42pm
examples-nonmonorepo Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 8:42pm
examples-svelte-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 8:42pm
examples-tailwind-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 8:42pm
examples-vite-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 8:42pm
turbo-site Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 8:42pm
1 Skipped Deployment
Project Deployment Actions Updated (UTC)
turborepo-test-coverage Skipped Skipped Open in v0 Jan 31, 2026 8:42pm

@anthonyshew anthonyshew requested a review from a team as a code owner January 31, 2026 20:41
@anthonyshew anthonyshew requested review from tknickman and removed request for a team January 31, 2026 20:41
@github-actions
Copy link
Copy Markdown
Contributor

Coverage Report

Metric Coverage
Lines 75.88%
Functions 46.74%
Branches 0.00%

View full report

@anthonyshew anthonyshew merged commit 54fdc5c into main Jan 31, 2026
107 checks passed
@anthonyshew anthonyshew deleted the fix/axios-ssrf-vulnerability branch January 31, 2026 20:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant