🛡️ CVE Monitor
Dịch vụ / phần mềm liên quan: Node.js / npm
⚠️ NVD chưa công bố điểm CVSS cho CVE này (thường do CVE vừa công bố, đang chờ NVD phân tích) — mức độ sẽ tự cập nhật ở lần đồng bộ sau.

Mô tả

Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure, Blob changes value handling, and a polluted visitor can execute when an attacker already has the stronger ability to inject a function. Serialized field naming and data interpretation can change, maxDepth can cause request failure, Blob can alter value handling, and a polluted visitor can execute under the stronger function-injection primitive. This issue is fixed in versions 0.34.0 and 1.20.0.

Chi tiết

Trạng tháiReceived
Điểm CVSS0.0 (v)
Vector CVSS
Ngày công bố01:17 29/09/2026
Ngày cập nhật01:17 29/09/2026
Nguồn dữ liệunvd

CWE

  • CWE-1321

Sản phẩm bị ảnh hưởng

Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.

Tài liệu tham khảo

Lịch sử thay đổi

Thời gianLoạiTrườngGiá trị cũGiá trị mới
01:17 29/09/2026 CREATED cve UNKNOWN

Tất cả thời gian trên trang này hiển thị theo giờ Việt Nam (GMT+7).