- run
pnpm installon the root, backend, and frontend directories - run
pnpm start:devon the root directory
This website is published on: https://axios-ssrf.onrender.com/
I specifically used a version of axios that is vulnerable to SSRF attacks.
- Go to the search bar and type an absolute URL like
http://example.com
The downloads middleware is vulnerable to path traversal attacks. Because this is not a conventional controller this can't be detected by the SAST tools (semgrep and checkmarx).