CVE-2025-27152Patch(axios / axios)

MEDIUMCVSS 5.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch axios axios systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • axios

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-03-31); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
axios

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-31: 1Mentions · 2026-04-10: 1Mentions · 2026-04-30: 1Mentions · 2026-09-28: 1Active Exploitation · 2026-04-10: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-10: 103-3104-1004-3009-28
Signal classification3 categories
Patch
133.3%
Active Exploitation
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-311
Patch1
2026-04-101
Active Exploitation1
2026-04-301
General1
Full discourse4 posts
  • runtz@runtzdev

    The first article of our SCA (Software Composition Analysis) series is live! In this first deep dive, we explore CVE-2025-27152 in Axios, a vulnerability that can lead to SSRF and credential leakage through absolute URLs. Subscribe to our newsletter. https://runtz.dev/newsletter/axios-absolute-url

    0102068
    4 followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: Storm-2755 Payroll Pirate - AiTM phishing hijacks Canadian M365 sessions, replays tokens via Axios 1.7.9 (CVE-2025-27152), reroutes Workday direct deposits. 9 detections, 18 IOCs. https://intel.threadlinqs.com/#TL-2026-0346 #ThreatIntel #AiTM #Workday https://t.co/l2tKtALzVQ

    Post summary

    The report details real‑world exploitation of CVE‑2025‑27152 via token replay in M365 sessions, with multiple detections, but provides no PoC, exploit code, or mitigation information.

    10010495
    19 followersView on X
  • Shadowcat Labs@shadowcatLabs
    General

    Group(betwick, vicduong, Hisokaaa) claims Polymarket compromise: 1,609-user PII DB, hardcoded API keys, CVE-2025-62718, CVE-2025-27152, CVE-2024-51479, and alleges $2.5M insider trading on US-Iran markets.

    Post summary

    The group alleges Polymarket compromise, citing three CVEs, but provides no evidence of exploitation, technical details, or remediation.

    00010647
    6 followersView on X
  • Stephane Thirion@archynet
    Patch

    A critical SSRF vulnerability in axios affects millions of Node.js apps. Here's how I audited 28+ Kubernetes apps and used NetworkPolicies to mitigate the risk. https://www.archy.net/cve-2025-27152-auditing-and-mitigating-axios-ssrf-in-kubernetes

    Post summary

    The post discusses a critical SSRF vulnerability in axios affecting many Node.js apps and explains how to mitigate it in Kubernetes using NetworkPolicies.

    00000247
    2.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaxiosaxios-node.js-

Explore more