OFF-CHAIN surface — axios does not ship on-chain; the deployed protocol bytecode is unaffected. Held for human review (not auto-dismissed) because of its surface / CVE class.
Surface analysis (triage-security-protocol)
Surface: off-chain (deploy-ops / HTTP-crypto stack)
On-chain: no — not compiled into bytecode
Verdict: NEEDS-HUMAN-REVIEW — HTTP client reached from the deploy/signing path (Ledger LedgerSigner and developer-supplied RPC / gas-oracle URLs) plus dev tooling. CVEs are credential-leak / Proxy-Authorization / SSRF / no_proxy-bypass / prototype-pollution class.
Consolidated: 30 open Dependabot advisories for axios, all resolved by a single bump.
Advisories (30)
GHSA-3g43-6gmg-66jw (high , scope=development) — axios Vulnerable to Credential Theft and Response Hijacking via Prototype P · alert feat: initial implementation on POL active management #228
GHSA-3g43-6gmg-66jw (high , scope=runtime) — axios Vulnerable to Credential Theft and Response Hijacking via Prototype P · alert chore: introducing forge deployment scripts and correcting names #220
GHSA-3w6x-2g7m-8v23 (medium , scope=runtime) — Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in · alert feat: Buy Back Burner set of contracts and Oracles #201
GHSA-445q-vr5w-6q77 (medium , scope=runtime) — Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type · alert refactor: historical inflation recalculation #204
GHSA-5c9x-8gcm-mpgx (medium , scope=runtime) — Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects · alert chore: proposal for target dispenser L2 migration #195
GHSA-5c9x-8gcm-mpgx (medium , scope=runtime) — Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects · alert refactor: separating updated and actual inflations #205
GHSA-62hf-57xw-28j9 (medium , scope=runtime) — Axios: unbounded recursion in toFormData causes DoS via deeply nested reque · alert doc: updating docs #196
GHSA-6chq-wfr3-2hj9 (high , scope=development) — Axios: Header Injection via Prototype Pollution · alert doc: updating docs #198
GHSA-6chq-wfr3-2hj9 (high , scope=runtime) — Axios: Header Injection via Prototype Pollution · alert Package dependencies update and goerli to legacy #193
GHSA-898c-q2cr-xwhg (medium , scope=runtime) — axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets · alert doc: re-audit 1.3.3 #218
GHSA-hfxv-24rg-xrqf (high , scope=runtime) — Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injecti · alert fix: Arbitrum staking deployment scripts #223
GHSA-j5f8-grm9-p9fc (high , scope=development) — Axios: Proxy-Authorization header leaks to redirect target when proxy is re · alert doc and chore: update changelog and correct target dispenser migration scripts #225
GHSA-j5f8-grm9-p9fc (high , scope=runtime) — Axios: Proxy-Authorization header leaks to redirect target when proxy is re · alert chore: adding script to change incentives fractions #221
GHSA-m7pr-hjqh-92cm (medium , scope=runtime) — Axios: no_proxy bypass via IP alias allows SSRF · alert chore: proposal scripts to update staking incentive params #197
GHSA-m7pr-hjqh-92cm (medium , scope=runtime) — Axios: no_proxy bypass via IP alias allows SSRF · alert chore: bbb deployment on Gnosis #203
GHSA-p92q-9vqr-4j8v (high , scope=development) — Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to- · alert Including link: https://hacken.io/ #227
GHSA-p92q-9vqr-4j8v (high , scope=runtime) — Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to- · alert chore: correcting base chain id #222
GHSA-pf86-5x62-jrwf (high , scope=development) — Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, · alert Update proposal_14_fund_contracts_from_leftovers_gnosis2.js #202
GHSA-pf86-5x62-jrwf (high , scope=runtime) — Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, · alert chore: L1 Mode message relayer address #192
GHSA-pjwm-pj3p-43mv (high , scope=runtime) — axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, al · alert chore: Addressing internal audit 2 #219
GHSA-pmwg-cvhr-8vh7 (high , scope=development) — Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via · alert refactor: tokenomics inflation update event #209
GHSA-pmwg-cvhr-8vh7 (high , scope=runtime) — Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via · alert chore: deployment on mode #189
GHSA-q8qp-cvcw-x6jj (high , scope=development) — Axios has prototype pollution read-side gadgets in HTTP adapter that allow · alert doc: re-audit 1.3.2 #208
GHSA-vf2m-468p-8v99 (medium , scope=runtime) — Axios: HTTP adapter streamed responses bypass maxContentLength · alert chore: deploy mode #194
GHSA-w9j2-pvgh-6h63 (medium , scope=development) — Axios: Authentication Bypass via Prototype Pollution Gadget in `validateSta · alert refactor: contract bytecode lenght optimization #210
GHSA-w9j2-pvgh-6h63 (medium , scope=runtime) — Axios: Authentication Bypass via Prototype Pollution Gadget in `validateSta · alert chore: correcting static audit flow #190
GHSA-xhjh-pmcv-23jw (low , scope=runtime) — Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams · alert chore: mode deployment scripts #188
GHSA-xhjh-pmcv-23jw (low , scope=runtime) — Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams · alert chore: adding proposal scripts #199
GHSA-xx6v-rp6x-q39c (medium , scope=development) — Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `w · alert chore: update tokenomics scripts #211
GHSA-xx6v-rp6x-q39c (medium , scope=runtime) — Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `w · alert chore and doc: Adding tag, updating the changelog #191
Threat model (deploy-ops)
This dependency is reached from the deploy/signing path (scripts/, deploy/), which talks only to developer-chosen endpoints (hardcoded vendor signing endpoints + developer-supplied RPC / gas-oracle URLs). This CVE class's precondition is a hostile proxy / redirect target / RPC / WebSocket server. An attacker who controls that endpoint can already lie about chain state, forge receipts, or front-run the deployment — a compromise that dominates the dep-level leak. So the CVE adds no marginal protocol risk over a threat the deployer accepts by trusting that endpoint.
Held for human review (not auto-dismissed) because it sits on the signing path — confirm the endpoints are genuinely developer constants/flags and not derived from untrusted input. If confirmed: bump for hygiene (free, zero on-chain impact, clears Dependabot noise); there is no exploitable hole. If a destination is attacker-influenced, this framing does not apply and the finding is genuinely applicable.
Suggested fix
Bump axios to >= 1.16.0 (transitive — pin via a resolutions entry in package.json if the root hasn't released a bumped range), then yarn install and re-run tests. One bump closes all advisories above.
Triaged by the triage-security-protocol skill (off-chain, consolidated per package). The Dependabot alerts remain open as the source of truth.
Surface analysis (triage-security-protocol)
LedgerSignerand developer-supplied RPC / gas-oracle URLs) plus dev tooling. CVEs are credential-leak / Proxy-Authorization / SSRF / no_proxy-bypass / prototype-pollution class.axios, all resolved by a single bump.Advisories (30)
Threat model (deploy-ops)
This dependency is reached from the deploy/signing path (
scripts/,deploy/), which talks only to developer-chosen endpoints (hardcoded vendor signing endpoints + developer-supplied RPC / gas-oracle URLs). This CVE class's precondition is a hostile proxy / redirect target / RPC / WebSocket server. An attacker who controls that endpoint can already lie about chain state, forge receipts, or front-run the deployment — a compromise that dominates the dep-level leak. So the CVE adds no marginal protocol risk over a threat the deployer accepts by trusting that endpoint.Held for human review (not auto-dismissed) because it sits on the signing path — confirm the endpoints are genuinely developer constants/flags and not derived from untrusted input. If confirmed: bump for hygiene (free, zero on-chain impact, clears Dependabot noise); there is no exploitable hole. If a destination is attacker-influenced, this framing does not apply and the finding is genuinely applicable.
Suggested fix
Bump
axiosto >= 1.16.0 (transitive — pin via aresolutionsentry in package.json if the root hasn't released a bumped range), thenyarn installand re-run tests. One bump closes all advisories above.Triaged by the
triage-security-protocolskill (off-chain, consolidated per package). The Dependabot alerts remain open as the source of truth.