OSV 1.4.0 · github-reviewed · 修改于 2026-05-13 00:19
发布时间
2026-05-08 02:30
GitHub 审查时间
2026-05-13 00:19
NVD 发布时间
2026-05-08 00:16
源文件
advisories/github-reviewed/2026/05/GHSA-587p-w43q-4hjx/GHSA-587p-w43q-4hjx.json
NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.
1.0.0