VDB
Sign up
MEDIUM4.7

GHSA-jj78-5fmv-mv28

Express Open Redirect vulnerability

Quick fix

GHSA-jj78-5fmv-mv28 — express: upgrade to the fixed version with the command below.

npm install express@4.0.0-rc1

Details

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0-rc1.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/express
Introduced in: 3.4.5Fixed in: 4.0.0-rc1
Fixnpm install express@4.0.0-rc1

References