Update dependency express to v4.20.0 #39
Security Report
You have successfully remediated 11 vulnerabilities, but introduced 12 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-616547-419802Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> express-4.20.0.tgz (Root Library) -> ❌ parseurl-1.3.3.tgz (Vulnerable Library) |
9.8 | Transitive parseurl-1.3.3.tgz |
express-4.20.0.tgz | None | ||
CVE-398484-724968Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> core-7.23.2.tgz (Root Library) -> traverse-7.29.0.tgz -> debug-4.4.3.tgz -> ❌ ms-2.1.3.tgz (Vulnerable Library) |
9.8 | Transitive ms-2.1.3.tgz |
core-7.23.2.tgz | None | ||
CVE-398484-724968Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> express-4.20.0.tgz (Root Library) -> serve-static-1.16.0.tgz -> send-0.18.0.tgz -> ❌ ms-2.1.3.tgz (Vulnerable Library) |
9.8 | Transitive ms-2.1.3.tgz |
express-4.20.0.tgz | None | ||
CVE-289561-266276Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> body-parser-1.20.3.tgz (Root Library) -> http-errors-2.0.0.tgz -> ❌ inherits-2.0.4.tgz (Vulnerable Library) |
9.8 | Transitive inherits-2.0.4.tgz |
body-parser-1.20.3.tgz | None | ||
CVE-2024-52798Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> express-4.20.0.tgz (Root Library) -> ❌ path-to-regexp-0.1.10.tgz (Vulnerable Library) |
7.5 | Transitive path-to-regexp-0.1.10.tgz |
express-4.20.0.tgz | Transitive path-to-regexp - 0.1.12 |
None | |
CVE-2025-13466Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ body-parser-1.20.3.tgz (Vulnerable Library) |
5.8 | Direct body-parser-1.20.3.tgz |
body-parser-1.20.3.tgz | body-parser - 2.2.1 | None | |
CVE-2024-47764Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> express-4.20.0.tgz (Root Library) -> ❌ cookie-0.6.0.tgz (Vulnerable Library) |
5.3 | Transitive cookie-0.6.0.tgz |
express-4.20.0.tgz | Transitive 0.7.0 |
None | |
CVE-2025-26791Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> ❌ dompurify-2.5.8.tgz (Vulnerable Library) |
4.5 | Direct dompurify-2.5.8.tgz |
dompurify-2.5.8.tgz | 3.2.4 | None | |
CVE-2026-2391Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> express-4.20.0.tgz (Root Library) -> ❌ qs-6.11.0.tgz (Vulnerable Library) |
3.7 | Transitive qs-6.11.0.tgz |
express-4.20.0.tgz | Transitive 6.14.2 |
None | |
CVE-2026-2391Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> body-parser-1.20.3.tgz (Root Library) -> ❌ qs-6.13.0.tgz (Vulnerable Library) |
3.7 | Transitive qs-6.13.0.tgz |
body-parser-1.20.3.tgz | Transitive 6.14.2 |
None | |
CVE-2025-15284Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> express-4.20.0.tgz (Root Library) -> ❌ qs-6.11.0.tgz (Vulnerable Library) |
3.7 | Transitive qs-6.11.0.tgz |
express-4.20.0.tgz | Transitive qs - 6.14.1 |
None | |
CVE-2025-15284Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> body-parser-1.20.3.tgz (Root Library) -> ❌ qs-6.13.0.tgz (Vulnerable Library) |
3.7 | Transitive qs-6.13.0.tgz |
body-parser-1.20.3.tgz | Transitive qs - 6.14.1 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2025-15284 | qs-6.5.2.tgz |
| CVE-2024-45296 | path-to-regexp-0.1.7.tgz |
| CVE-2026-2391 | qs-6.5.2.tgz |
| CVE-2024-45590 | body-parser-1.18.3.tgz |
| CVE-2022-24999 | qs-6.5.2.tgz |
| CVE-2024-43800 | serve-static-1.13.2.tgz |
| CVE-2025-13466 | body-parser-1.18.3.tgz |
| CVE-275296-826791 | qs-6.5.2.tgz |
| CVE-2024-10491 | express-4.16.4.tgz |
| CVE-2024-43796 | express-4.16.4.tgz |
| CVE-2024-52798 | path-to-regexp-0.1.7.tgz |
Base branch total remaining vulnerabilities: 68
Base branch commit: 83155abda4658ac651ce8161120d08a2098f9f70
Total libraries scanned: 442
Scan token: fb0f0fa5ae9643cbb2188d4f063be5ef