Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Chan154

#33629of 57,427
8.3Total CVSS
Vulnerabilities · 1
PT-2026-99952
8.3
2026-09-28
Npm · Axios · CVE-2026-101909
**Name of the Vulnerable Software and Affected Versions** Axios versions 0.28.0 through 0.33.x Axios versions 1.15.1 through 1.19.x **Description** ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution, a condition where an attacker can manipulate the prototype of an object to inject properties. A separate same-process prototype pollution flaw allows the supply of inherited `dots`, `indexes`, `metaTokens`, `maxDepth`, `visitor`, or `Blob` values before object serialization. These inherited options can alter field naming and data interpretation in toFormData, while `maxDepth` can force request failure and `Blob` can change value handling. Additionally, a polluted `visitor` can execute if an attacker possesses the ability to inject a function. **Recommendations** Update to version 0.34.0. Update to version 1.20.0.