CVE-2026-42042Axios · Axios
Vulnerability data via NVD (ingested)
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXSRFToken config property. When this property is set to any truthy non-boolean value (via prototype pollution or misconfiguration), the same-origin check (isURLSameOrigin) is short-circuited, causing XSRF tokens to be sent to all request targets including cross-origin servers controlled by an attacker. This vulnerability is fixed in 1.15.1 and 0.31.1.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-42042product:"Axios Axios"http.html:"Axios"More intel sources (5)
vuln:CVE-2026-42042vulnerabilities.cve_id: CVE-2026-42042CVE-2026-42042CVE-2026-42042"CVE-2026-42042" exploit -site:nvd.nist.gov