GHSA-9f6g-j8ch-79g4
morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
Quick fix
GHSA-9f6g-j8ch-79g4 — morgan: upgrade to the fixed version with the command below.
npm install morgan@1.12.1Details
### Impact
Morgan writes attacker-controlled request data to the access log. Its escaping (added in 1.11.0 and 1.12.0) neutralizes control characters, the Unicode line separators, and backslash, but not the double quote (`0x22`), which is the field delimiter of the Apache combined log format morgan emits. An attacker who controls a quoted field (`:user-agent`, `:referrer`, the request URL, or the Basic auth `:remote-user`) can inject a double quote to close the field early and forge additional fields in the log record. The `combined`, `common`, and `default` formats, and any custom format that quotes a token, are affected. This is an incomplete fix of CVE-2026-5078 and CVE-2026-15603.
### Patches
Users should upgrade to version 1.12.1.
### Workarounds
Update to version 1.12.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-87859[ADVISORY]
- https://github.com/expressjs/morgan/commit/4b695edf967ce179cdf4009fe8cddd184b7511ee[WEB]
- https://cna.openjsf.org/security-advisories.html[WEB]
- https://github.com/expressjs/morgan[PACKAGE]
- https://github.com/expressjs/morgan/releases/tag/1.12.1[WEB]