Echo: axios: security update to 0.33.0

high Tenable Cloud Security Plugin ID 457859

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled
proxy. axios hardens merged request configuration by creating a null-prototype object, but request
interceptors run after the merge; a common immutable interceptor pattern such as {...config} or
Object.assign({}, config) converts the hardened config back into a regular object. axios then dispatches
that object without re-hardening it, and the Node HTTP adapter reads config.proxy through the prototype
chain. If an attacker can pollute Object.prototype.proxy, affected requests can be routed through an
attacker-controlled proxy. For plaintext HTTP requests, the proxy can observe Authorization headers, Basic
auth from config.auth, method, absolute URL, Host, and request body, and can return its own response. This
does not establish browser impact or HTTPS header/body disclosure under normal TLS validation. Affected
versions are >=0.31.1 (fixed in 0.33.0) and >=1.15.2 (fixed in 1.18.0). (CVE-2026-67320)

Solution

Update the axios library and its related packages to version 0.33.0 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-67320

Plugin Details

Severity: High

ID: 457859

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.63

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-67320

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.3

Threat Score: 6.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 7/20/2026

Reference Information

CVE: CVE-2026-67320

IAVA: 2026-A-0804