axios is vulnerable to Prototype Pollution
77
High Risk
Several security vulnerabilities were quietly patched in axios version 1.6.4 and version 0.29.0. Notably, a prototype pollution flaw impacted the formDataToJSON function, posing a significant risk. Additionally, a Regular Expression Denial of Service (ReDoS) vulnerability was identified and fixed in the combineURLs function.
You are affected by this flaw if you use the formDataToJSON function. This is more likely to happen in a front-end than in a backend.
axios is vulnerable to Prototype Pollution in versions 0.1.0 - 0.28.1 and 1.0.0 - 1.6.3.
To fix, either freeze the prototype or upgrade to axios 1.6.4 or above.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant