Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2025-63704: Query-Parser-String for NPM: Malicious Query Parameters Can Harm Your App

CVE-2025-63704 GHSA-587p-w43q-4hjx
Summary

The query-parser-string package for NPM doesn't properly check user input, which can cause unexpected behavior in your application. This can happen if you use user-supplied data in your application without proper validation. To stay safe, update to a newer version of the package or consider using an alternative solution.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
Ecosystem VendorProductAffected versions
npm – query-string-parser 1.0.0
Original title
query-parser-string is vulnerable to Prototype Pollution
Original description
NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.
Vulnerability type
CWE-1321 Prototype Pollution
Published: 7 May 2026 · Updated: 23 May 2026 · First seen: 7 May 2026