None severity0.0NVD Advisory· Published Jan 29, 2025· Updated Jun 17, 2026
CVE-2024-57965
CVE-2024-57965
Description
In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/axios/axios/commit/0a8d6e19da5b9899a2abafaaa06a75ee548597dbnvdPatch
- github.com/axios/axios/pull/6714nvdIssue TrackingPatch
- github.com/axios/axios/issues/6351nvdIssue Tracking
- github.com/axios/axios/releases/tag/v1.7.8nvdRelease Notes
News mentions
0No linked articles in our index yet.