axios is vulnerable to Prototype Pollution
52
Medium Risk
Affected versions of this package are vulnerable to prototype pollution–based header injection due to unsafe FormData detection and header merging logic. The affected implementation may treat attacker-controlled plain objects as valid FormData instances and invoke inherited getHeaders methods from polluted prototypes, allowing malicious headers such as forged authorization values to be merged into outbound requests. In addition, query parameter encoding improperly handles null-byte values, which can lead to unexpected parameter transformations. An attacker able to influence object prototypes or request data can inject unauthorized headers or manipulate request processing.
You are affected if you are using a version that falls within the vulnerable range.
axios is vulnerable to Prototype Pollution in versions 1.0.0 - 1.15.0 and 0.0.1 - 0.31.0.
Upgrade the axios library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant