Skip to content

Conversation

@soinclined
Copy link
Contributor

@soinclined soinclined commented Oct 2, 2025

Security: Override axios to 1.12.0 to fix DoS vulnerability

Summary

Added npm package override to force axios to version 1.12.0 across all dependencies to address a reported DoS vulnerability. The n8n-nodes-crossmint package currently uses [email protected] as a transitive dependency through n8n-workflow, and this override ensures the secure version is used instead.

Review & Testing Checklist for Human

  • Verify override takes effect: Run npm install and check that axios resolves to 1.12.0 in node_modules or package-lock.json
  • Test n8n node functionality: Install this package in an n8n instance and verify that both CrossmintWallets and CrossmintCheckout nodes still function correctly
  • Validate HTTP requests: Test that API calls to Crossmint services work properly with the new axios version (create test wallets, process checkout flows)

Notes

  • This is part of a coordinated security upgrade across multiple Crossmint repositories to fix the same axios DoS vulnerability
  • axios 1.12.0 should be backward compatible with 1.8.2, but dependency overrides can sometimes cause unexpected behavior
  • The change only affects the resolved version of axios - no code changes were made to the actual n8n node implementations

Session: https://app.devin.ai/sessions/bf609251d888444a94f5721a1ad5292c
Requested by: @soinclined

@devin-ai-integration
Copy link
Contributor

Original prompt from Penelope
in crossmint/server-stellar-wallets crossmint/crossmint-onramp crossmint/trump-frontend and crossmint/worldstore-emailer, is it possible to upgrade axios to version 1.12.0 without breaking anything else?

@devin-ai-integration
Copy link
Contributor

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment and CI monitoring

@soinclined soinclined requested a review from manu-xmint October 7, 2025 15:52
@manu-xmint manu-xmint closed this Oct 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants