Skip to content

[Snyk] Security upgrade axios from 1.2.1 to 1.12.0#40

Open
karencapiiro wants to merge 1 commit into
mainfrom
snyk-fix-a3bbf881ede13277ebb465425f04d507
Open

[Snyk] Security upgrade axios from 1.2.1 to 1.12.0#40
karencapiiro wants to merge 1 commit into
mainfrom
snyk-fix-a3bbf881ede13277ebb465425f04d507

Conversation

@karencapiiro

Copy link
Copy Markdown

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • website/package.json
  • website/package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-AXIOS-12613773
  89  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling

@socket-security

Copy link
Copy Markdown

@rafikmojr

Copy link
Copy Markdown
Collaborator

Logo
Checkmarx One – Scan Summary & Detailsdaa9bcc1-ee85-4bd6-a823-14400ba875fe

New Issues (30)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
CRITICAL CVE-2025-29927 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. In 11.1.4 through 12.3.5, 13.x prior to 13.5.9, 14.x prior to 14.2.25, 14.3....
Attack Vector: NETWORK
Attack Complexity: LOW

ID: lJOd%2FtMAZBI5IMVhstd4lvPBRszBiJ8EAPUuvohS2fA%3D
Vulnerable Package
HIGH CVE-2024-12905 Npm-tar-fs-2.1.1
detailsRecommended version: 2.1.3
Description: An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: PfpotgWQQzpy9a6Z2jO%2BJ%2BDoABGSQsouEO1Ipz4Po3Q%3D
Vulnerable Package
HIGH CVE-2024-21538 Npm-cross-spawn-7.0.3
detailsRecommended version: 7.0.5
Description: Versions of the package cross-spawn prior to 6.0.6 and 7.x prior to 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS), due to im...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 3QV4gfskpMOUrhFEZ6aAkQukhLa8JJqm6wnpx3fb01U%3D
Vulnerable Package
HIGH CVE-2024-4068 Npm-braces-3.0.2
detailsRecommended version: 3.0.3
Description: The NPM package "braces", versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: EABz1KTGsUAembuhd1%2B%2B1IKkPr6R8i7IS%2FchXxUlMAM%3D
Vulnerable Package
HIGH CVE-2024-47831 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React Framework for the Web. It contains a vulnerability in the image optimization feature that allows for a potential Denial of Servi...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: zfosjz3D%2Faved026v1uULsIWYDC1hocWSQb8uRCJd%2FM%3D
Vulnerable Package
HIGH CVE-2024-51479 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. In versions 9.5.5-canary.0 through 14.2.14 and 14.3.0-canary.0 through 15.0....
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 0i07sfl7l1MEUiZdcMg%2BC85jEzaKLXiSCu%2B7d4a7%2FzE%3D
Vulnerable Package
HIGH CVE-2025-48387 Npm-tar-fs-2.1.1
detailsRecommended version: 2.1.3
Description: The package tar-fs provides filesystem bindings for tar-stream. In versions prior to 1.16.5, 2.0.x prior to 2.1.3, and 3.0.x prior to 3.0.9, there ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: xRfORHADOpaMj%2BNAtpp7Gw0JdixDdIR1oLAjNwcyS28%3D
Vulnerable Package
HIGH CVE-2025-57822 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. In versions through 14.2.31, 14.3.0-canary.0 through 15.4.2-canary.42 and 15...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Tx%2FiYwIkNdvmh1fe2jOLccD%2BXZGkV4XPWWcMAsN9%2BBY%3D
Vulnerable Package
HIGH Reflected_XSS /website/src/pages/api/update_task.ts: 25
detailsThe method Cx7b0b8fb6 embeds untrusted data in generated output with json, at line 78 of /website/src/pages/api/update_task.ts. This untrusted d...
ID: xirmicHWO8TwpgnQdFz%2Bm6WUvTk%3D
Attack Vector
HIGH Reflected_XSS /website/src/pages/api/new_task/[task_type].ts: 15
detailsThe method Cx0a033392 embeds untrusted data in generated output with json, at line 71 of /website/src/pages/api/new_task/[task_type].ts. This...
ID: FgP3Hn5pmfWQul9C2QAbLmB7vIc%3D
Attack Vector
MEDIUM CVE-2024-28176 Npm-jose-4.11.1
detailsRecommended version: 4.15.5
Description: The package jose is a JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JW...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: u5NkVtErrTqQjwA6uDvOpFqvs1N7MwKcNYm%2FOpO3GgU%3D
Vulnerable Package
MEDIUM CVE-2024-34064 Python-Jinja2-3.1.2
detailsRecommended version: 3.1.6
Description: Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: xE4kN6uzydioiMvhDR1gbKZauYSb9fhCpiFkD48Dyl8%3D
Vulnerable Package
MEDIUM CVE-2024-35195 Python-requests-2.28.1
detailsRecommended version: 2.32.4
Description: Requests is an HTTP library. In the package requests versions prior to 2.32.0, when making requests through a Requests `Session`, if the first requ...
Attack Vector: LOCAL
Attack Complexity: HIGH

ID: l4yiFuJnKD0%2BO4DLDbicYe4h5S4gpZpkP3k%2FW4Wz23Y%3D
Vulnerable Package
MEDIUM CVE-2024-3772 Python-pydantic-1.9.1
detailsRecommended version: 1.10.13
Description: Regular expression denial of service in Pydanic allows remote attackers to cause denial of service via a crafted email string. This issue affects p...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: Z9M8%2B89vYCgRAVoagktGQqZK40KOwonDNhgyVD72TnY%3D
Vulnerable Package
MEDIUM CVE-2024-4067 Npm-micromatch-4.0.5
detailsRecommended version: 4.0.8
Description: The NPM package "micromatch" prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in "micromatch....
Attack Vector: NETWORK
Attack Complexity: LOW

ID: JygdB7i8XeIU1Exbd9xlrrhHIlk%2Bgy3sU6YiHkdyWjs%3D
Vulnerable Package
MEDIUM CVE-2024-47081 Python-requests-2.28.1
detailsRecommended version: 2.32.4
Description: Requests is an HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak ".netrc" credentials to third parties for speci...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: W4wNqiCagHYZGPUr5kiN5%2FF08lAw0MIMlYgayUt5was%3D
Vulnerable Package
MEDIUM CVE-2024-47764 Npm-cookie-0.5.0
detailsRecommended version: 0.7.0
Description: The NPM package cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cook...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: YN9H4OCmQzS7hGhHjXtQ5Nj6HBaj8M6%2BimmYGgF803o%3D
Vulnerable Package
MEDIUM CVE-2024-55565 Npm-nanoid-3.3.4
detailsRecommended version: 3.3.8
Description: The package nanoid versions through 3.3.7 and 4.0.0 through 5.0.8 mishandle non-integer values.
Attack Vector: NETWORK
Attack Complexity: LOW

ID: j0i%2F%2BIFUB95Z%2FgQqVLv2Hfs0e8OlwLnPhYK8PqNWyr0%3D
Vulnerable Package
MEDIUM CVE-2024-56201 Python-Jinja2-3.1.2
detailsRecommended version: 3.1.6
Description: Jinja is an extensible templating engine. In affected versions, a bug in the Jinja compiler allows an attacker that controls both the content and f...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: vJrM8T%2B6LIWef5tESDvDRucctUkVBPRirjO%2B7gCXyBs%3D
Vulnerable Package
MEDIUM CVE-2024-56326 Python-Jinja2-3.1.2
detailsRecommended version: 3.1.6
Description: Jinja is an extensible templating engine. In affected versions, an oversight in how the Jinja sandboxed environment detects calls to `str.format` a...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: 2lwQjHIVNOh9gMvIEPHjpTRmC4gemYdf9BkB0Ddiqys%3D
Vulnerable Package
MEDIUM CVE-2024-56332 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 through 13.5.7, 14.0.0 through 14.2.20, and 15.0....
Attack Vector: NETWORK
Attack Complexity: LOW

ID: YnA7kooXFcH0n2oAqjPCMZN8MJBgzMS2u8q%2BBFc3OUA%3D
Vulnerable Package
MEDIUM CVE-2025-27516 Python-Jinja2-3.1.2
detailsRecommended version: 3.1.6
Description: Jinja is an extensible templating engine. In Jinja2 versions prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: R9ib5pJAvcmgcQGpSZrZWit%2FVlea%2FbWFKXXrSpWhhO4%3D
Vulnerable Package
MEDIUM CVE-2025-27789 Npm-@babel/runtime-corejs3-7.20.6
detailsRecommended version: 7.26.10
Description: Babel is a compiler for writing next-generation JavaScript. In affected versions of Babel, to compile regular expressions named capturing groups, B...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: 7Py2eq6u%2Bvd41AvUDdQnNyKoWmyG4Vfy%2F70ELFuGpDA%3D
Vulnerable Package
MEDIUM CVE-2025-27789 Npm-@babel/helpers-7.20.6
detailsRecommended version: 7.26.10
Description: Babel is a compiler for writing next-generation JavaScript. In affected versions of Babel, to compile regular expressions named capturing groups, B...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: B1UhEH%2FSok%2B59GgW7FLgKBINe4GOfEDcaJt6K0Ad0gk%3D
Vulnerable Package
MEDIUM CVE-2025-50181 Python-urllib3-1.26.20
detailsRecommended version: 2.5.0
Description: The package urllib3 is a user-friendly HTTP client library for Python. In versions prior to 2.5.0, it is possible to disable redirects for all requ...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: e6LpLjGxIcKARIa1wY%2F8Ev1bKMl90tcJT7MfWfRFv%2FU%3D
Vulnerable Package
MEDIUM CVE-2025-54121 Python-starlette-0.22.0
detailsRecommended version: 0.47.2
Description: Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In v...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: nOvHLiLAQTS6yn6en2xQmjH2UbmOM%2BQH6H2crNcscgY%3D
Vulnerable Package
MEDIUM CVE-2025-57752 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. In versions 0.9.9 through 14.2.30, 14.3.0-canary.0 through 15.4.2-canary.18,...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: qybKiEHls%2Fjxk3cZr1ya2%2BCbMwfFksTTJUAXB7zKphI%3D
Vulnerable Package
LOW CVE-2025-48068 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. In the next package, versions 13.0.0 through 15.2.2-canary.2 may have allowe...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: k1uLcL9fdYK8vigXStYXzrCRHI7kUJGCBMyfaYZaEu4%3D
Vulnerable Package
LOW CVE-2025-55173 Npm-next-13.0.6
detailsRecommended version: 14.2.32
Description: Next.js is a React framework for building full-stack web applications. In versions through 14.2.30, 15.0.0-rc.0 through 15.4.2-canary.18, 15.4.3 an...
Attack Vector: ADJACENT NETWORK
Attack Complexity: LOW

ID: Uq0IqUvJQ1ljHwPlLezAYnQsZbo%2FU9o6VJ1%2FK7HdU3w%3D
Vulnerable Package
LOW CVE-2025-5889 Npm-brace-expansion-1.1.11
detailsRecommended version: 1.1.12
Description: A vulnerability was found in juliangruber brace-expansion. It has been rated as problematic. Affected by this issue is the function "expand" of the...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: 2tT21ck1wiIOXKcVfh65QNvN5Vy4yqm2O43R7cnh3hk%3D
Vulnerable Package
Fixed Issues (39)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
HIGH Cx89601373-08db Npm-debug-2.6.9
HIGH Cx89601373-08db Npm-debug-3.2.7
HIGH Cxab55612e-3a56 Npm-braces-3.0.2
HIGH Cxca84a1c2-1f12 Npm-micromatch-4.0.5
HIGH Reflected_XSS /website/src/pages/api/new_task/[task_type].ts: 28
HIGH Reflected_XSS /website/src/pages/api/update_task.ts: 25
HIGH Reflected_XSS /website/src/pages/api/new_task/[task_type].ts: 15
MEDIUM CVE-2023-26159 Npm-follow-redirects-1.15.2
MEDIUM CVE-2023-45857 Npm-axios-1.2.1
MEDIUM Host Namespace is Shared /docker-compose.yaml: 11
MEDIUM Host Namespace is Shared /docker-compose.yaml: 5
MEDIUM Host Namespace is Shared /docker-compose.yaml: 11
MEDIUM Host Namespace is Shared /docker-compose.yaml: 50
MEDIUM Host Namespace is Shared /docker-compose.yaml: 19
MEDIUM Host Namespace is Shared /docker-compose.yaml: 19
MEDIUM Host Namespace is Shared /docker-compose.yaml: 18
MEDIUM Host Namespace is Shared /docker-compose.yaml: 27
MEDIUM Host Namespace is Shared /docker-compose.yaml: 18
MEDIUM Host Namespace is Shared /docker-compose.yaml: 26
MEDIUM Host Namespace is Shared /docker-compose.yaml: 27
MEDIUM Host Namespace is Shared /docker-compose.yaml: 4
MEDIUM Host Namespace is Shared /docker-compose.yaml: 5
MEDIUM Networks Not Set /docker-compose.yaml: 27
MEDIUM Networks Not Set /docker-compose.yaml: 11
MEDIUM Networks Not Set /docker-compose.yaml: 5
MEDIUM Networks Not Set /docker-compose.yaml: 18
MEDIUM Networks Not Set /docker-compose.yaml: 4
MEDIUM Networks Not Set /docker-compose.yaml: 19
MEDIUM Networks Not Set /docker-compose.yaml: 5
MEDIUM Networks Not Set /docker-compose.yaml: 26
MEDIUM Networks Not Set /docker-compose.yaml: 27
MEDIUM Networks Not Set /docker-compose.yaml: 18
MEDIUM Networks Not Set /docker-compose.yaml: 50
MEDIUM Networks Not Set /docker-compose.yaml: 11
MEDIUM Networks Not Set /docker-compose.yaml: 19
MEDIUM SSRF /website/src/pages/api/new_task/[task_type].ts: 15
LOW Missing_CSP_Header /website/src/lib/poster.ts: 4
LOW Unsafe_Use_Of_Target_blank /website/src/components/CallToAction.tsx: 19
LOW Unsafe_Use_Of_Target_blank /website/src/components/CallToAction.tsx: 34

Use @Checkmarx to reach out to us for assistance.

Just send a PR comment with @Checkmarx followed by a natural language request.

Examples: @Checkmarx how are you able to help me? @Checkmarx rescan this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants