The latest versions of both 4.x and 5.x are using Axios versions < 1.7.5 and as such are subject to known vulnerabilities as per: https://security.snyk.io/package/npm/axios
We've had this flagged up in a pen test, which indicates the issue stems from this script: /freeform/plugin.js. I couldn't see any reference to vulnerable axios versions in your package.json files, but noticed some precompiled files in packages/plugin so I'm assuming those are where the issue lies.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2026-01-15T22:41:39Z",
"nvd_published_at": null,
"severity": "LOW"
}