PT-2026-99952 · Npm · Axios

·

CVE-2026-101909

·

Published

2026-09-28

·

Updated

2026-10-01

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Axios versions 0.28.0 through 0.33.x Axios versions 1.15.1 through 1.19.x
Description ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution, a condition where an attacker can manipulate the prototype of an object to inject properties. A separate same-process prototype pollution flaw allows the supply of inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. These inherited options can alter field naming and data interpretation in toFormData, while maxDepth can force request failure and Blob can change value handling. Additionally, a polluted visitor can execute if an attacker possesses the ability to inject a function.
Recommendations Update to version 0.34.0. Update to version 1.20.0.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101909
GHSA-X97P-JQ2G-JP4F

Affected Products

Axios