Skip to content
Threat Feed

Vendor

Axios

4 briefs RSS
high advisory

Axios Node.js HTTP Adapter Vulnerable to Proxy Redirection via Prototype Pollution Bypass

A vulnerability in Axios's Node.js HTTP adapter, affecting versions 1.15.2 and 1.16.0, allows an attacker to bypass prototype pollution hardening, enabling redirection of HTTP requests through an attacker-controlled proxy to achieve sensitive information disclosure.

axios prototype-pollution information-disclosure nodejs
2t
high advisory

ClickFix Campaign Activity

Tracking brief for the ClickFix campaign; individual sightings are folded in as reported.

open source packages +44 campaign clickfix
22i updated
critical advisory

Axios Prototype Pollution Leads to Man-in-the-Middle Vulnerability

Axios is vulnerable to a Prototype Pollution attack that can be escalated into a full Man-in-the-Middle (MITM) attack by injecting a malicious proxy configuration via `Object.prototype.proxy`, allowing attackers to intercept, read, and modify all HTTP traffic, including authentication credentials.

axios prototype-pollution mitm javascript
3r 7t
critical advisory

Axios Library Vulnerable to Cloud Metadata Exfiltration via Header Injection

The Axios library is vulnerable to a header injection chain that allows prototype pollution in a third-party dependency to be escalated into remote code execution or full cloud compromise via AWS IMDSv2 bypass by polluting Object.prototype with CRLF characters to smuggle requests to the AWS Metadata Service.

Axios crlf-injection prototype-pollution aws-metadata ssrf
2r 4t 2i