Skip to content

Vulnerability in Archon project #1053

@ankitdn

Description

@ankitdn

While working on Archon project, I scanned the dependency manifest and found that the application uses a vulnerable version of axios affected by CVE-2025-62718. This vulnerability allows bypassing NO_PROXY rules due to improper hostname normalization (e.g., localhost. or [::1]). As a result, requests intended to bypass proxies may instead be routed through a proxy, potentially exposing sensitive internal services and leading to SSRF risks.

CVE Report
CVE Link

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2Medium priority - Backlog, when time permitsarea: infraDocker, deployment, CI/CDbugSomething is brokeneffort/lowSingle file or function, one responsibility, isolated change

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions