Prototype pollution in axios - CVE-2026-44489
Published: May 29, 2026 / Updated: May 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation in "setProxy()" function in lib/adapters/http.js. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in data manipulation.
Affected software
IBM Security SOAR
How to mitigate CVE-2026-44489
IBM Security SOAR - update to 51.0.10.2