PT-2026-38453 · Npm · Query-Parser-String

Published

2026-05-07

·

Updated

2026-05-08

·

CVE-2025-63704

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions query-parser-string version 1.0.0
Description The software is subject to Prototype Pollution, a condition where an attacker can manipulate the prototype of an object to alter the behavior of the application. This occurs because the package fails to properly sanitize user-supplied query parameters before merging them into a newly created object.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2025-63704
GHSA-587P-W43Q-4HJX

Affected Products

Query-Parser-String