- Published on
axios is the HTTP client most JavaScript and Node apps use to make requests. While reading through it, our security agent KLUE found a bug in how axios chooses the request method. On the default axios object, if another flaw in your app has polluted Object.prototype, a call you wrote as a safe GET can quietly go out as a DELETE, POST, PUT, or PATCH. Here is how KLUE found it, why only some ways of calling axios are affected, and how it was fixed.