Looking for the vulnerability index of Invicti's legacy products?
axios : Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') V (CVE-2026-101909) - Vulnerability Database

axios : Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') V (CVE-2026-101909)

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure,

Related Vulnerabilities