FlowFuse / FlowFuse/node-red-dashboard

Security: Update axios dependency due to multiple published CVEs

Open
#2,138 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
HTML
Stars
355
Forks
82
Avg merge
4d 23h
Merged PRs (30d)
24

Description

The current release of `node-red-dashboard` (v1.30.2) depends on `axios` v1.13.2.

Several published CVEs are reported for this version of axios:

* CVE-2026-42043
* CVE-2026-42044
* CVE-2026-42264
* CVE-2026-25639
* CVE-2026-42033
* CVE-2026-42035
* CVE-2026-42038

These findings are reported by common SBOM and vulnerability management tools.

We are currently preparing products for compliance with the European Cyber Resilience Act (CRA). As part of the CRA requirements, vulnerabilities in software components and transitive dependencies must be assessed and documented. This currently results in multiple findings related to the axios dependency used by the dashboard.

Is there already a plan to update axios to a version that addresses these CVEs?

Any information regarding a planned update or roadmap would be appreciated.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.