mirror of
https://github.com/infiniflow/ragflow.git
synced 2026-07-30 12:39:27 +08:00
## Summary Upgrade axios from 1.15.1 to 1.15.2 to fix CVE-2026-42264. ## Vulnerability | Field | Value | |-------|-------| | **ID** | CVE-2026-42264 | | **Severity** | HIGH | | **Scanner** | trivy | | **Rule** | `CVE-2026-42264` | | **File** | `agent/sandbox/sandbox_base_image/nodejs/package-lock.json` | | **Assessment** | Likely exploitable | **Description**: axios: Axios: Prototype pollution allows information disclosure and request manipulation --- *Automated security fix by [OrbisAI Security](https://orbisappsec.com)*