Junglewise Threat Intelligence

CVE-2026-42033: Axios prototype pollution gadgets in mergeConfig

CVE-2026-42033 · Severity: high · CVSS 7.4 · Published 2026-04-24

Technologies: Axios. Vendors: Axios.

Executive brief

Axios is a widely used library for making web requests in Node.js and browser applications. A vulnerability exists where an attacker can exploit a separate flaw in a different part of the application to hijack Axios's internal settings. This allows the attacker to silently intercept sensitive data like login credentials, or modify the data received from web services before the application processes it, potentially leading to unauthorized actions or data theft.

Technical details

Axios fails to use hasOwnProperty guards when reading certain configuration keys such as 'parseReviver' and 'transport' during the mergeConfig process. If an attacker can achieve prototype pollution via a co-dependency (e.g., vulnerable versions of lodash), they can inject malicious functions into Object.prototype. These 'gadgets' allow the attacker to intercept and modify JSON responses via the parseReviver function or completely hijack the HTTP adapter by providing a malicious transport object. This can lead to the exfiltration of request headers, bodies, and credentials. The vulnerability is fixed in versions 1.15.1 and 0.31.1.

Affected products

  • Axios axios <=1.15.0, <=0.31.0

Timeline

  • 2026-04-24: disclosed
  • 2026-04-24: advisory
  • 2026-04-24: patched

References

Related threats