Npm · Axios · CVE-2026-101902
**Name of the Vulnerable Software and Affected Versions**
Axios versions 0.27.2 through 0.33.x
Axios versions prior to 1.20.0
**Description**
Default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If Object.prototype.method is polluted by another vulnerability in the same process, calls such as `axios.request({ url })` and `axios({ url })` may send a state-changing HTTP method instead of the default GET. This issue acts as a read-side gadget in the request dispatch process, meaning it allows an existing prototype pollution to be leveraged for unexpected behavior.
**Recommendations**
Update to version 0.34.0.
Update to version 1.20.0.