
Cursor added axios. Three deps on the tree. A hundred packages under them. The pin was ^1.6.0. npm audit hit SSRF. CVE-2024-39338. The model never saw 1.7.4. Scan the tree, not just the file it wrote. npx -y safeweave-mcp
Post summary
The tweet reports that npm audit identified an SSRF vulnerability (CVE‑2024‑39338) in axios ^1.6.0, without providing any PoC, exploit, or patch information.

