AI analysis
Axios 1.15.2 through versions before 1.20.0 leaves the Node.js HTTP adapter (lib/adapters/http.js) without its own createConnection on the request options it passes to Node. If a separate same-process prototype-pollution flaw has placed a function on Object.prototype.createConnection, Node resolves and calls that inherited socket factory when Axios issues a request. The attacker-controlled factory can choose the transport endpoint, receive request headers and bodies including credentials, and return attacker-controlled responses while the URL still looks legitimate. Node.js applications on those Axios releases are affected; the issue is conditional on that prototype-pollution primitive (CVSS 4.0 7.6, attack requirements present, low privileges). It is fixed in 1.20.0, is not in CISA KEV, and no public proof-of-concept is known.
What to do: Upgrade Axios to 1.20.0 or later and pin dependencies so 1.15.2 through pre-1.20.0 cannot be reintroduced. Separately remove any same-process prototype-pollution path that could set Object.prototype.createConnection, and investigate unexpected outbound connections or credential use from Node services that were on a vulnerable release.
Affected
| axios | 1.15.2 up to, but not including, 1.20.0 |
Estimated exposure
masson the order of millions of Node.js applications (only Axios 1.15.2 through versions before 1.20.0, Node HTTP adapter) — Estimate from Axios’s long-standing place among the most installed npm HTTP clients, with a very large Node.js dependent-project base; the advisory gives no install count for the 1.15.2–pre-1.20.0 slice, and exploitation also requires a…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a function on Object.prototype.createConnection. Node resolves and invokes the inherited createConnection socket factory, allowing the attacker-controlled function to select the transport endpoint. The attacker endpoint can receive request headers and bodies, including credentials, and return attacker-controlled responses while the URL appears legitimate. This issue is fixed in version 1.20.0.