Disclosure summary
## Summary Axios form serialization reads `visitor`, `maxDepth`, `dots`, `indexes`, `metaTokens`, and `Blob` from an internal options object without own-property guards. When `Object.prototype` has been polluted elsewhere in the same process, those inherited values can change how axios serializes multipart and URL-encoded request bodies. Axios does not create the prototype pollution source. This is a read-side gadget: axios turns an existing same-process pollution condition into altered request serialization or request failures. ## Impact The impact depends on which property is polluted and which axios serialization path the application uses. Polluted `dots`, `indexes`, or `metaTokens` can change field names and cause the receiving service to parse different data than the caller intended. Polluted `maxDepth` can cause nested form submissions to throw `ERR_FORM_DATA_DEPTH_EXCEEDED`, producing request-level or service-level denial of service for affected workflows. Polluted `visitor` can execute as the serializer visitor if an attacker can place a function on `Object.prototype`, but that condition generally implies a stronger same-process code-execution or malicious-dependency primit
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-x97p-jq2g-jp4f
Open original source · Updated Sep 30, 2026
Axios: Prototype Pollution Gadget in axios toFormData Options
Source severity: HIGH / 8.3
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | axios | >= 0.28.0, < 0.34.0 | 0.34.0 |
| npm | axios | >= 1.15.1, < 1.20.0 | 1.20.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-30T11:02:45-04:00
MODIFIED 2026-09-30T11:02:48-04:00
INGESTED 2026-10-06T11:43:09-04:00