Description
NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.
Recommendation
No fix is available yet. Followings are affected versions:
- = 1.0.0
References
Related Issues
- expr-eval vulnerable to Prototype Pollution - CVE-2025-13204
- expr-eval vulnerable to Prototype Pollution - expr-eval - CVE-2025-13204
- mpregular vulnerable to prototype pollution - CVE-2025-57323
- min-document vulnerable to prototype pollution - CVE-2025-57352
You might also like:
- Tags:
- npm
- query-string-parser
Anything's wrong? Let us know Last updated on May 12, 2026


