CVE-2025-63704

CRITICAL9.8EPSS 0.02%

query-parser-string is vulnerable to Prototype Pollution

發布日:2026/5/7修改日:2026/5/12

描述

NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(5)