CVE-2026-40175
CVE Details
Visit the official vulnerability details page for CVE-2026-40175 to learn more.
Initial Publication
04/10/2026
Last Update
04/16/2026
Third Party Dependency
axios
NIST CVE Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.3.1, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0 and 0.3.1.
CVE Severity
Our Official Summary
Investigation is ongoing to determine how this vulnerability affects our products.
Status
Undergoing Analysis
Affected Products & Versions
| Version | PaletteAI | PaletteAI VerteX |
|---|---|---|
| 1.0.7 | ⚠️ Impacted | ⚠️ Impacted |
Revision History
No revisions available.