

AppSec5 min
SCA Deep Dive #1 — Axios (CVE-2025-27152) - Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
Axios can ignore baseURL when the path is already an absolute URL. The request goes elsewhere and the default headers can go with it.