Repository navigation
chore(repo): Update dependency axios@<0.33.0 to v0.34.0 [SECURITY] - #10059
renovate[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
@clerk/astro
@clerk/backend
@clerk/chrome-extension
@clerk/clerk-js
@clerk/electron
@clerk/electron-passkeys
@clerk/eslint-plugin
@clerk/expo
@clerk/expo-biometrics
@clerk/expo-google-signin
@clerk/expo-passkeys
@clerk/express
@clerk/fastify
@clerk/hono
@clerk/localizations
@clerk/mosaic
@clerk/nextjs
@clerk/nuxt
@clerk/react
@clerk/react-router
@clerk/shared
@clerk/tanstack-react-start
@clerk/testing
@clerk/ui
@clerk/upgrade
@clerk/vue
commit: |
This PR contains the following updates:
0.33.0→0.34.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Axios: Prototype Pollution Gadget in axios toFormData Options
CVE-2026-101909 / GHSA-x97p-jq2g-jp4f
More information
Details
Summary
Axios form serialization reads
visitor,maxDepth,dots,indexes,metaTokens, andBlobfrom an internal options object without own-property guards. WhenObject.prototypehas been polluted elsewhere in the same process, those inherited values can change how axios serializes multipart and URL-encoded request bodies.Axios does not create the prototype pollution source. This is a read-side gadget: axios turns an existing same-process pollution condition into altered request serialization or request failures.
Impact
The impact depends on which property is polluted and which axios serialization path the application uses.
Polluted
dots,indexes, ormetaTokenscan change field names and cause the receiving service to parse different data than the caller intended. PollutedmaxDepthcan cause nested form submissions to throwERR_FORM_DATA_DEPTH_EXCEEDED, producing request-level or service-level denial of service for affected workflows. Pollutedvisitorcan execute as the serializer visitor if an attacker can place a function onObject.prototype, but that condition generally implies a stronger same-process code-execution or malicious-dependency primitive and should be described carefully.Affected Functionality
Affected:
axios.toFormData().transformRequestpaths that serialize plain objects tomultipart/form-data.formSerializeroption defaults when the relevant properties are absent as own properties.Not affected:
toFormData().Object.prototypeis not polluted.Technical Details
lib/helpers/toFormData.jsmerges caller options with defaults usingutils.toFlatObject(). Whenoptionsisundefined,toFlatObject()returns the default object unchanged:That default object has
Object.prototypein its prototype chain.toFormData()then reads behavior-affecting values directly:These reads can resolve inherited polluted properties.
Local code review confirmed the direct reads in
v1.18.1. Tag checks show the option-based form serializer exists inv0.28.0and later;maxDepthappears in the1.xline from the form recursion fix.Proof of Concept of Attack
Constrained local demonstration:
Expected safe behavior is that the default max depth is used unless the caller sets an own
formSerializer.maxDepth. Current behavior reads the inherited value and can throwERR_FORM_DATA_DEPTH_EXCEEDED.For serializer alteration, polluting
Object.prototype.dots = truechanges nested field naming from bracket notation to dot notation when the caller did not opt into that behavior.Workarounds
Avoid serializing attacker-controlled objects as form data in a process with known prototype pollution. As a partial mitigation, callers can pass an own
formSerializerobject that sets explicit safe values for all relevant keys, includingvisitor,maxDepth,dots,indexes,metaTokens, andBlob.Original report
Summary
axios v1.18.1 contains a read-side prototype pollution gadget in its form data serialization logic. Six option properties (
visitor,maxDepth,dots,indexes,metaTokens,Blob) are read from a plain JavaScript object that inherits fromObject.prototypewithouthasOwnPropertyguards. WhenObject.prototypehas been polluted elsewhere in the process a common consequence of compromised transitive npm dependencies, these polluted values silently control axios' form serialization behavior.The highest-impact gadget is
visitor: a polluted function onObject.prototype.visitoris invoked for every key-value pair during multipart and URL-encoded form serialization, receiving the value, key, path, and internal helper functions as arguments.Details
Root Cause
The attack chain has three steps:
Step 1:
formSerializeris read safely, butundefinedflows throughIn
lib/defaults/index.js, the defaulttransformRequestfunction readsformSerializerfrom config using theown()helper, which enforceshasOwnProp:When the user does not explicitly configure
formSerializer, this correctly returnsundefined. Thatundefinedis then passed as theoptionsparameter totoFormData():Step 2:
toFlatObjectreturns a plain-object defaultInside
lib/helpers/toFormData.js,options(which isundefined) is merged with defaults viautils.toFlatObject():toFlatObjecthas an early-return for null/undefined sources:Since
optionsisundefined, the function returnsdestObjunchanged — the plain object{ metaTokens: true, dots: false, indexes: false }. This object's prototype isObject.prototype.Step 3: Options are read without
hasOwnPropguardsThe six option properties are read directly from the plain object:
None of these reads use
utils.hasOwnProp(). Since theoptionsobject inherits fromObject.prototype, any property set onObject.prototypeby a compromised dependency is resolved through the prototype chain.Why the Existing Defenses Didn't Catch This
axios has extensive prototype pollution defenses. However, those defenses are all focused on the config object (created by
mergeConfig, which returnsObject.create(null)). ThetoFormDatafunction creates its own internal options object that sits outside that boundary, and the 6 reads on that internal object were never audited.PoC
Reproduction Steps
Environment
Any environment with Node.js and npm. Tested on:
- Node.js v24.15.0, npm 11.13.0
- axios v1.18.1 (latest release at time of writing)
Step 1: Create a fresh project
mkdir axios-pp-poc cd axios-pp-poc npm init -y npm install axios@1.18.1Step 2: Create the PoC file
Create
poc.mjswith the following content:Step 3: Run the PoC
Impact
1. Data Exfiltration via
visitor(Confidentiality: High)A polluted
Object.prototype.visitorfunction is called as the form data visitor:The attacker receives:
-
value— the raw value being serialized (passwords, tokens, PII, API keys)-
key— the field name-
path— the full path array (e.g.,['profile', 'address', 'street'])-
exposedHelpers— internal helpers includingdefaultVisitor,convertValue,isVisitableBy delegating to
helpers.defaultVisitor, the attack is completely transparent, the request succeeds normally and the server receives intact data. The exfiltration is invisible to both the caller and the server.2. Denial of Service via
maxDepth(Availability: Low)A polluted
Object.prototype.maxDepthof1or2causes any moderately nested form data request to throwERR_FORM_DATA_DEPTH_EXCEEDED. Applications that send nested objects as form data (common with APIs that acceptprofile[name],address[city], etc.) will experience mysterious failures.3. Data Corruption via
dots,indexes,metaTokens(Integrity: Low)Polluting these options changes the serialization format of form field names:
-
dots: true— changes bracket notation (user[name]) to dot notation (user.name)-
indexes: true— changes array serialization (items[]) to indexed (items[0],items[1])-
metaTokens: false— changesobj{}keys to raw json stringsThe server may misinterpret the submitted form data, leading to silent data corruption.
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method
CVE-2026-101902 / GHSA-9fr6-4gfg-395g
More information
Details
Summary
Axios default-instance requests that omit an explicit method can read an inherited
methodvalue fromObject.prototype. If another vulnerability in the same process pollutesObject.prototype.method, calls such asaxios.request({ url })andaxios({ url })can send a state-changing HTTP method instead of the expected defaultGET.Axios does not create the prototype pollution source. This is a read-side gadget in axios request dispatch.
Impact
In an affected application with a separate prototype-pollution primitive, an attacker can change axios default-instance requests that omit
methodfromGETto methods such asDELETE,POST,PUT, orPATCH. The practical impact depends on the target endpoint and can include unintended writes, deletion, or other state changes.Method aliases such as
axios.get(url)and requests with an explicit ownmethodare not affected by the confirmed method path.Affected Functionality
Affected:
axios.request({ url }).axios({ url }).config.methodis provided.Not affected in the confirmed method PoC:
axios.get(url)and other method aliases.axios.request({ url, method: 'GET' }).axios.create().request({ url })when the created instance defaults are produced by currentmergeConfig()and do not inherit fromObject.prototype.Technical Details
lib/core/Axios.jssets the request method with:mergeConfig()now returns a null-prototype request config, soconfig.methodis safe fromObject.prototype. However, the default axios instance stores the module defaults object asthis.defaults, and that defaults object is a normal object. IfObject.prototype.methodexists,this.defaults.methodresolves to the polluted inherited value.Local verification on axios
1.18.1showed a default-instanceaxios.request({ url })request reaching a loopback server asDELETEafterObject.prototype.method = 'DELETE'.Proof of Concept of Attack
Constrained local demonstration:
Expected safe behavior is a
GETrequest. Current affected behavior sendsDELETEon the default instance when no method is provided.Workarounds
Use explicit method aliases such as
axios.get()or set an ownmethodon request configs. Avoid default-instance shorthand for requests in processes where prototype pollution is suspected or possible.Original report
Summary
Axios
1.17.0contains a read-side prototype-pollution gadget in the default Axios instance. If another vulnerability in the same Node.js process pollutesObject.prototype.method, default-instance calls such asaxios.request({ url })andaxios({ url })can be forced to use an attacker-controlled HTTP method, such asDELETE, instead of the expected defaultGET.Axios does not create the prototype pollution by itself. The issue is that Axios reads fallback values from
this.defaultswithout an own-property guard, allowing inherited values fromObject.prototypeto influence request behavior.This should be treated as a prototype-pollution gadget, not as a standalone prototype-pollution source. In other words, Axios is not the component that lets the attacker write to
Object.prototype; Axios is the component that becomes dangerous afterObject.prototypehas already been polluted by another bug in the same process.Details
The vulnerable fallback read is in
lib/core/Axios.js:The merged request
configis created as a null-prototype object inlib/core/mergeConfig.js:Therefore, when the caller does not provide
config.method, the fallback becomes:The default Axios instance uses the module defaults object. In the tested version, that defaults object is affected by inherited properties from
Object.prototype. IfObject.prototype.methodis polluted,this.defaults.methodresolves to that inherited value and Axios uses it as the request method.The same unsafe inherited-property pattern also affects
this.defaults.allowAbsoluteUrls, which can change how absolute URLs are combined withbaseURL.Proof of Concept
Access and Attack Conditions
No admin access is required for Axios itself. This is a library-level gadget.
The attacker must have an existing way to pollute
Object.prototypein the same Node.js process, for example through a separate prototype-pollution vulnerability in another dependency or application input path. Axios is the gadget that turns that pollution into dangerous HTTP request behavior.Required condition:
What Axios contributes:
What Axios does not do:
Affected usage:
Not affected in the confirmed PoC:
Reproduction Steps
1.17.0:Object.prototype.method = "DELETE", default-instance calls that omit an explicit method are sent asDELETE.What the Method PoC Script Does
The PoC starts a temporary local HTTP server for each Axios call and records the HTTP method received by that server. It then simulates an already-existing prototype-pollution condition by setting:
While that pollution is active, the script sends five Axios requests:
The script then deletes the polluted property:
Finally, it prints the method observed by the local server for each request. The vulnerable behavior is confirmed when the default Axios instance sends
DELETEforaxios.request({ url })andaxios({ url }), while the safe comparison paths still sendGET.Method Override PoC
Create
validate-prototype-method-gadget.mjs:Run:
Observed result:
The local server received:
This confirms that inherited
Object.prototype.methodcontrols the default method for vulnerable default-instance request paths.Supporting
allowAbsoluteUrlsGadget EvidenceThe same inherited-property issue affects
allowAbsoluteUrls.Create
validate-prototype-allowabsoluteurls-gadget.mjs:Observed result:
Without pollution, Axios sends the request to the absolute URL. After
Object.prototype.allowAbsoluteUrls = false, the default Axios instance combines the absolute URL withbaseURLand sends the request to the base server instead. An instance created withaxios.create()remains unaffected.Impact
This is a prototype-pollution gadget. It becomes exploitable when an application has any separate prototype-pollution primitive that allows an attacker to set properties on
Object.prototypein the same Node.js process.If such pollution is possible, an attacker can influence Axios default-instance requests that omit an explicit method:
axios.request({ url })axios({ url })This can turn an expected safe default
GETrequest into a state-changing method such as:DELETEPOSTPUTPATCHPotential impact includes unauthorized state-changing requests, deletion of resources, unintended writes, data corruption, or denial of service when the target endpoint treats the HTTP method as security-relevant.
The issue does not require admin access to Axios itself, but it does require an existing prototype-pollution path in the application. Applications that always use explicit methods, method aliases such as
axios.get(), or isolated instances created throughaxios.create()are not affected by the confirmed method-override path.Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
axios/axios (axios@<0.33.0)
v0.34.0Compare Source
v0.34.0 — September 13, 2026
This release hardens request configuration and proxy handling, adds caller diagnostics and cancellation context, and tightens TypeScript header types.
🔒 Security Fixes
🚀 New Features
🐛 Bug Fixes
🔧 Maintenance & Chores
Full Changelog: axios/axios@v0.33.0...v0.34.0
Configuration
📅 Schedule: (in timezone GMT)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.