CVE-2025-63704

NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.
Configurations

No configuration.

History

08 May 2026, 22:16

Type Values Removed Values Added
CWE CWE-1321
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

07 May 2026, 18:50

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 16:16

Updated : 2026-05-08 22:16


NVD link : CVE-2025-63704

Mitre link : CVE-2025-63704

CVE.ORG link : CVE-2025-63704


JSON object : View

Products Affected

No product.

CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')