Executive brief
query-string-parser is an NPM package used to parse URL query strings. It fails to properly sanitize user-supplied parameters, allowing an attacker to inject malicious properties that pollute the object prototype. This can lead to unexpected behavior in applications using the library, potentially compromising confidentiality, integrity, or availability depending on how the library is integrated.
Technical details
The vulnerability is a prototype pollution issue (CWE-1321) in the query-string-parser NPM package versions through 1.0.0. The root cause is in the _fillValue function within index.js, which fails to properly sanitize user-supplied query parameters before merging them into the returned object. An attacker can craft a malicious query string containing __proto__ properties (e.g., "a=1&b=2&__proto__[polluted]=polluted") and pass it to the fromQuery function. This causes the prototype of all objects to be polluted with attacker-controlled properties, potentially leading to unexpected application behavior or further exploitation. The attack requires network access to applications that parse untrusted query strings using this library, with no authentication or user interaction required. No patched version is indicated in the available advisory data.
Affected products
- npm query-string-parser 1.0.0 and prior
Timeline
- 2026-05-07: disclosed: Advisory published
- 2023-09-03: other: Vulnerability initially reported