CVE-2025-63704

Published
View on NVD ↗
CVSS v3
9.8
CRITICAL
CVSS v2
N/A
Affected
2
PROJECTS

Description

NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.

Rack style query string parser for Node.js
GitHubGitHub
8
Rack style query string parser for Node.js.
NPMNPM