PT-2026-35053 · Npm · Axios

August829

·

Published

2026-04-24

·

Updated

2026-06-05

·

CVE-2026-42044

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Axios versions 1.0.0 through 1.15.1
Description Axios is a promise based HTTP client for the browser and Node.js. The library is susceptible to a Prototype Pollution Gadget attack. This occurs because the default transformResponse function calls JSON.parse(data, this.parseReviver), where this is the merged config object. Since parseReviver is not present in defaults, not validated by assertOptions, and lacks constraints, a polluted Object.prototype.parseReviver function is executed for every key-value pair in every JSON response. This allows an attacker to selectively modify individual values in JSON API responses, which can lead to privilege escalation, balance manipulation, and authorization bypass.
Recommendations Update Axios to version 1.15.2.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-BE61221
CLEANSTART-2026-LC05413
CVE-2026-42044
GHSA-3W6X-2G7M-8V23

Affected Products

Axios