← לוח פגיעויות

CVE-2025-63704

קריטית 9.8

תיאור (מקור, אנגלית)

NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-1/8/2026
CWE
CWE-1321

קישורים