NVD - CVE-2026-40175
DRANK

ReceivedThis CVE record has recently been published to the CVE List and has been included within the NVD dataset.DescriptionAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0.Metrics NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.CVSS 4.0 Severity and Vector Strings:CVSS 3.x Severity and Vector Strings:CNA:  GitHub, Inc.Vector:  CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCVSS 2.0 Severity and Vector Strings:Weakness EnumerationCWE-IDCWE NameSourceCWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')GitHub, Inc.  CWE-444Inconsistent I…

nvd.nist.gov
Related Topics: Vulnerability
2 comments
  • とはいえだな、、、「プロトタイプ汚染されたライブラリがある」の時点で「家の鍵を掛け忘れてる」みたいなもんだからな。。。

  • プロトタイプ汚染されたライブラリがあるとして、それとaxiosの脆弱性であるSSRFとCRLFインジェクションとリクエストスマグリングを組み合わせることでRCEを起こして、 AWS IMDSv2 bypass するのか。芸術点の高い脆弱性を突いてる。 nvd.nist.gov/vuln/detail/CV…