CVE-2024-39338Active Exploitation(axios / axios)

LOWCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for axios axios systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • axios

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-15); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
axios

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-15: 1Mentions · 2026-08-24: 1Active Exploitation · 2026-04-15: 1Technical Details · 2026-04-15: 1Technical Details · 2026-08-24: 104-1508-24
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-04-151
Active Exploitation1
2026-08-241
General1
Full discourse2 posts
  • Nick Flux@NickGStacked
    General

    Cursor added axios. Three deps on the tree. A hundred packages under them. The pin was ^1.6.0. npm audit hit SSRF. CVE-2024-39338. The model never saw 1.7.4. Scan the tree, not just the file it wrote. npx -y safeweave-mcp

    Post summary

    The tweet reports that npm audit identified an SSRF vulnerability (CVE‑2024‑39338) in axios ^1.6.0, without providing any PoC, exploit, or patch information.

    1102154
    66 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Active Exploitation

    🔒 #CyberSecurity CVE-2024-39338: Active Exploitation of Marimo Pre-Auth RCE — Defense & Remediat… "Security teams utilizing Marimo, the open-source reactive notebook for Python, are facing a…" 🔗 https://securityarsenal.com/blog/cve-2024-39338-active-exploitation-of-marimo-pre-auth-rce-defense-and-remediation #CyberSecurity #ThreatIntel #vulnerability #cve #patch

    Post summary

    The post announces that CVE‑2024‑39338, a pre‑authentication RCE in Marimo, is currently being exploited in the wild, but does not provide PoC, exploit code, or remediation details in the snippet.

    0000039
    10 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaxiosaxios-node.js-

Explore more