Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[2c] Replace axios (CVE-2023-45857) with native fetch

Open
#22 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
58/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Quiet
Tech stack
javascript
Domain
api, security

Research direction

Inspect fetchRemoteData and fetchRemoteDataBlob in src/Utils.js, then check package.json and the lock file for axios. Run npm install after removing the dependency and verify both methods use the browser fetch API, the lock file is updated, and axios no longer appears in the dependency tree.

Written by the indexing model from the issue text.

Description

Summary

Replace axios with native fetch to eliminate unpatched CVE-2023-45857 / SSRF vulnerability

Environment

  • Product/Service: FeatureSET-Display — JavaScript API
  • File: src/Utils.js
  • Dependency: axios 0.26.x

Problem Description

axios 0.26.x has unpatched CVEs including CVE-2023-45857 (SSRF). The two Utils.js methods (fetchRemoteData, fetchRemoteDataBlob) only use axios.get(url, { responseType: 'arraybuffer' }) — functionality natively available in the browser via fetch().then(r => r.arrayBuffer()). Replacing axios removes the vulnerability entirely and eliminates a runtime dependency.

Expected Behavior

fetchRemoteData and fetchRemoteDataBlob use the browser-native fetch API. axios is removed from package.json. No CVEs remain from this dependency.

Actual Behavior

axios 0.26.x is bundled and shipped with unpatched SSRF vulnerability CVE-2023-45857.

Error Details

CVE-2023-45857 — axios <=1.5.1: SSRF via crafted request
Severity: High
Affected: axios 0.26.x (current)

Tasks

  • Replace fetchRemoteData in src/Utils.js with a fetch-based implementation
  • Replace fetchRemoteDataBlob in src/Utils.js with a fetch-based implementation
  • Remove axios from package.json dependencies and run npm install to update the lock file

Impact

High — Unpatched security vulnerability (CVE-2023-45857 / SSRF) shipped in the bundle. Fix is a one-line change per method.

Additional Context

Replacement pattern:

async fetchRemoteData(url) {
  const res = await fetch(url);
  return res.arrayBuffer();
}

No external dependency needed. Works in all modern browsers and Node 18+.

Dominant language
JavaScript
Stars
8
Forks
2
PR merge metrics
No merged PRs in 30d

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from webarkit/FeatureSET-Display

All issues in webarkit/FeatureSET-Display

Similar issues

More JavaScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.