CVE-2020-28168: Axios

Medium severity, CVSS 5.9. EPSS: 2.4% chance of exploitation in the next 30 days.

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

Affected products

  • Axios Axios: from 0.19.0, up to and including 0.21.0
  • Siemens Sinec Ins: before 1.0 (fixed in 1.0); version 1.0 only

Published 2020-11-06. Last modified 2026-06-17.