GHSA-587p-w43q-4hjx
CRITICALCVE-2025-63704NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.
- Affected
- = 1.0.0
- Fixed in
- not stated
- Weakness
- CWE-1321
- Published
- 2026-05-07
- Source
- github