logo

Critical Axios Vulnerability Enables Remote Code Execution, PoC Released

ID: 59ccb651-06f6-5e85-a47c-712a274df325

STIX ID: report--59ccb651-06f6-5e85-a47c-712a274df325

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-13

Date Updated: 2026-04-22

Author: Divya

...
...

A critical CVE-2026-40175 was disclosed in the Axios npm package that allows header injection and HTTP request smuggling via prototype pollution gadgets, permitting attackers to bypass AWS IMDSv2 and exfiltrate cloud metadata and IAM credentials; the flaw has a CVSS 3.1 score of 9.9, a public PoC was published, and maintainers advise updating vulnerable Axios versions to 1.15.0 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.