VDB
Sign up
CRITICAL9.8

GHSA-587p-w43q-4hjx

query-parser-string is vulnerable to Prototype Pollution

Details

NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/query-string-parser

No fixed version published yet for query-string-parser (npm). Pin to a known-safe version or switch to an alternative.

References