PT-2025-48543 · Unknown · Express.Js
Published
2025-12-01
·
Updated
2025-12-02
·
CVE-2024-51999
CVSS v4.0
2.7
Low
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions
Express.js versions prior to 5.2.0
Express.js versions prior to 4.22.0
Description
Express.js, a minimalist web framework for Node.js, is affected by an issue where the
request.query object inherits all object prototype properties when using the extended query parser ('query parser': 'extended'). This allows query string parameter keys that match property names to overwrite these properties. The issue is present in versions using the extended query parser.Recommendations
Update to Express.js version 5.2.0 or later.
Update to Express.js version 4.22.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Express.Js