CVE-2025-63704
NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2025-63704, https://github.com/victorteokw/query-string-parser/issues/3, https://gist.github.com/6en6ar/d62f614dbb2b1032b5e45a56fe26ec8b, https://github.com/victorteokw/query-string-parser, https://www.npmjs.com/package/query-string-parser?activeTab=readme
