CVE-2025-63704

CRITICAL

query-parser-string 1.0.0 - Prototype Pollution

Title source: llm
STIX 2.1

Description

NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.

Scores

CVSS v3 9.8
EPSS 0.0002
EPSS Percentile 5.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1321
Status published
Products (1)
npm/query-string-parser npm
Published May 07, 2026
Tracked Since May 07, 2026