IM
IronMonkey Threat Research

CVE-2026-40175 MEDIUM

Published: 2026-04-10 | Last Modified: 2026-05-20 | Status: Modified

Description

Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.

CVSS Metrics

Base Score: 4.8 (MEDIUM)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactLOW
Integrity ImpactLOW
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 2.2

Impact Score: 2.5

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-113
en CWE-444
en CWE-918

Affected Products

Vendor Product Version Update Type
axios axios * <built-in method update of dict object at 0x7b070ba86140> Application
axios axios * <built-in method update of dict object at 0x7b070c1c6dc0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*
Yes cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*
Notification
Message here