VYPR
None severity0.0NVD Advisory· Published Jan 29, 2025· Updated Jun 17, 2026

CVE-2024-57965

CVE-2024-57965

Description

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Axios/Axios3 versions
    cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*+ 2 more
    • cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*range: <1.7.8
    • (no CPE)range: <1.7.8
    • (no CPE)range: 0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.