Skip to content

build(deps): patch axios security vulnerability#1598

Open
ethan-ozelius-contentful wants to merge 1 commit intomainfrom
DX-728/axios-vuln
Open

build(deps): patch axios security vulnerability#1598
ethan-ozelius-contentful wants to merge 1 commit intomainfrom
DX-728/axios-vuln

Conversation

@ethan-ozelius-contentful
Copy link
Contributor

@ethan-ozelius-contentful ethan-ozelius-contentful commented Feb 14, 2026

Summary

Patch a security vulnerability in axios.

https://contentful.atlassian.net/browse/ZEND-7627

https://contentful.atlassian.net/browse/DX-728

https://security.snyk.io/package/npm/axios/1.13.4

Affected versions of this package are vulnerable to Prototype Pollution via the mergeConfig function. An attacker can cause the application to crash by supplying a malicious configuration object containing a proto property, typically by leveraging JSON.parse().
How to fix Prototype Pollution?
Upgrade axios to version 1.13.5 or higher.

PR Checklist

  • I have read the CONTRIBUTING.md file
  • All commits follow conventional commits
  • Documentation is updated (if necessary)
  • PR doesn't contain any sensitive information
  • There are no breaking changes

@ethan-ozelius-contentful ethan-ozelius-contentful requested a review from a team as a code owner February 14, 2026 17:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant