CVE-2025-63704
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/05/2026
Last modified:
08/05/2026
Description
NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



