Skip to main content

CVE-2026-67313

CVE Details​

Visit the official vulnerability details page for CVE-2026-67313 to learn more.

Initial Publication​

08/01/2026

Last Update​

09/01/2026

Third Party Dependency​

axios

NIST CVE Summary​

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception.

CVE Severity​

7.5

Our Official Summary​

Investigation is ongoing to determine how this vulnerability affects our products.

Status​

Analyzed

Affected Products & Versions​

VersionPaletteAIPaletteAI VerteX
1.4.0⚠️ Impacted⚠️ Impacted
1.3.2⚠️ Impacted⚠️ Impacted

Revision History​

No revisions available.