CRITICAL9.8
GHSA-587p-w43q-4hjx
query-parser-string is vulnerable to Prototype Pollution
Details
NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/query-string-parser
No fixed version published yet for query-string-parser (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-63704[ADVISORY]
- https://github.com/victorteokw/query-string-parser/issues/3[WEB]
- https://gist.github.com/6en6ar/d62f614dbb2b1032b5e45a56fe26ec8b[WEB]
- https://github.com/victorteokw/query-string-parser[PACKAGE]
- https://www.npmjs.com/package/query-string-parser?activeTab=readme[WEB]