Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rwr8-xrpw-9qf5

Опубликовано: 15 янв. 2026
Источник: github
Github: Прошло ревью

Описание

solspace/craft-freeform Exposed to Known Axios Vulnerabilities via Precompiled Assets

Summary

The latest versions of both 4.x and 5.x are using Axios versions < 1.7.5 and as such are subject to known vulnerabilities as per: https://security.snyk.io/package/npm/axios

Details

We've had this flagged up in a pen test, which indicates the issue stems from this script: /freeform/plugin.js. I couldn't see any reference to vulnerable axios versions in your package.json files, but noticed some precompiled files in packages/plugin so I'm assuming those are where the issue lies.

Пакеты

Наименование

solspace/craft-freeform

composer
Затронутые версииВерсия исправления

< 4.1.22

4.1.22

Наименование

solspace/craft-freeform

composer
Затронутые версииВерсия исправления

>= 5.0.0-beta.1, < 5.5.9

5.5.9