PT-2026-99948 · Npm · Axios
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Axios versions 1.15.2 through 1.19.x
Description
The Node HTTP adapter in
lib/adapters/http.js provides request options that lack a specific createConnection value. When a separate prototype pollution flaw is present in the same process, an attacker can place a function on Object.prototype.createConnection. Node then resolves and executes this inherited socket factory, enabling the attacker to control the transport endpoint. This allows the attacker to intercept request headers and bodies, including credentials, and provide malicious responses while the URL remains seemingly legitimate.Recommendations
Update to version 1.20.0.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Axios