express is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
60
Medium Risk
A vulnerability has been identified in the Express response.links function, allowing arbitrary resource injection into the Link header when unsanitized data is used. The issue arises from improper sanitization of Link header values, which allows characters like ,, ;, and <> to preload malicious resources. This vulnerability is particularly concerning when dynamic parameters are involved.
You are affected if you are using a version that falls within the vulnerable range.
express is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 3.0.0-alpha1 - 3.21.2.
Upgrade the express library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant