PT-2026-99952 · Npm · Axios
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Axios versions 0.28.0 through 0.33.x
Axios versions 1.15.1 through 1.19.x
Description
ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution, a condition where an attacker can manipulate the prototype of an object to inject properties. A separate same-process prototype pollution flaw allows the supply of inherited
dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. These inherited options can alter field naming and data interpretation in toFormData, while maxDepth can force request failure and Blob can change value handling. Additionally, a polluted visitor can execute if an attacker possesses the ability to inject a function.Recommendations
Update to version 0.34.0.
Update to version 1.20.0.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Axios