FlowFuse / FlowFuse/node-red-dashboard
Security: Update axios dependency due to multiple published CVEs
- Dominant language
- HTML
- Stars
- 355
- Forks
- 82
- Avg merge
- 4d 23h
- Merged PRs (30d)
- 24
Description
The current release of `node-red-dashboard` (v1.30.2) depends on `axios` v1.13.2.
Several published CVEs are reported for this version of axios:
* CVE-2026-42043
* CVE-2026-42044
* CVE-2026-42264
* CVE-2026-25639
* CVE-2026-42033
* CVE-2026-42035
* CVE-2026-42038
These findings are reported by common SBOM and vulnerability management tools.
We are currently preparing products for compliance with the European Cyber Resilience Act (CRA). As part of the CRA requirements, vulnerabilities in software components and transitive dependencies must be assessed and documented. This currently results in multiple findings related to the axios dependency used by the dashboard.
Is there already a plan to update axios to a version that addresses these CVEs?
Any information regarding a planned update or roadmap would be appreciated.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.