Executive brief
Axios, a widely used tool for making web requests in JavaScript applications, is vulnerable to a security flaw that could allow attackers to manipulate web traffic. By exploiting a weakness in how Axios handles data from other components, an attacker could potentially steal sensitive cloud credentials or gain unauthorized access to internal systems. This could lead to a full compromise of cloud environments like AWS or the execution of malicious code on the server.
Technical details
Axios versions prior to 1.15.0 and 0.31.0 are vulnerable to a 'gadget' attack chain. The vulnerability occurs when prototype pollution in a third-party dependency is used to inject unsanitized header values into outbound HTTP requests. This can be escalated to achieve Server-Side Request Forgery (SSRF), specifically bypassing AWS IMDSv2 protections to exfiltrate cloud metadata, or potentially achieving Remote Code Execution (RCE). The attack requires a precondition of a prototype pollution vulnerability existing elsewhere in the application's dependency tree. Patches are available in versions 1.15.0 and 0.31.0.
Affected products
- Axios Axios < 1.15.0, < 0.31.0
Timeline
- 2026-04-10: advisory: Initial publication date
- 2026-04-06: patched: Fix for cloud metadata exfiltration committed
- 2026-04-11: patched: Backported fixes committed to v0.x branch
References
- https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c
- https://github.com/axios/axios/commit/363185461b90b1b78845dc8a99a1f103d9b122a1
- https://github.com/axios/axios/pull/10660
- https://github.com/axios/axios/pull/10688
- https://github.com/axios/axios/releases/tag/v0.31.0
- https://github.com/axios/axios/releases/tag/v1.15.0
- https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx