Summary
Togoder Security scanned the npm package express@4.19.2 on Oct 4, 2026. An AI review of 12 source files produced 1 high, 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Prototype Pollution
NPS-639A5154F5E8
The code explicitly sets opts.allowPrototypes = true when options.allowPrototypes is undefined. This disables a security protection in the qs module that prevents properties like __proto__ and constructor from being parsed, allowing prototype pollution via query string parameters. An attacker can craft a query string such as ?__proto__[polluted]=yes to inject arbitrary properties into Object.prototype, potentially leading to denial of service, privilege escalation, or remote code execution depending on downstream usage.
Dynamic module loading with computed input
NPS-64DB8FE38166
The View constructor derives a module name from the file extension (this.ext.slice(1)) and passes it directly to require(mod). While this is standard Express behavior for loading view engines, if an attacker can control the extension or engine name (e.g., via user input that reaches defaultEngine or a view name with an attacker-controlled extension), it could allow loading of arbitrary installed modules. This is a known risk surface in Express and should be treated as a potential vector for module loading abuse.
File system path traversal potential
NPS-DE83FB5C067F
The lookup and resolve methods construct file paths by joining root with a user-supplied name using path.resolve/path.join. If name contains traversal sequences (e.g., ../), it could escape the intended view directory and resolve files outside the root. This is a classic directory traversal risk, though Express typically sanitizes view names at a higher level. The code itself does not enforce containment within root.
Synchronous file system access
NPS-A24BED336A60
fs.statSync is used in tryStat to check file existence synchronously. While not malicious, synchronous I/O in a view resolution path can be abused for denial-of-service (blocking the event loop) if called with many crafted view names. This is a minor performance/security concern.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/middleware/query.js | medium | The query middleware intentionally enables allowPrototypes for backwards compatibility, reintroducing a known prototype pollution vulnerability in the qs parser. |
| lib/view.js | medium | The code is the legitimate Express View module with no overt malicious patterns, but it contains inherent risks around dynamic module loading via file extension and potential path traversal in view lookup that could be abused if inputs are not properly sanitized upstream. |
| index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/application.js | safe | This is the standard Express.js application module (lib/application.js) with no malicious patterns; all requires, logic, and exports are consistent with the legitimate, widely-used express framework. |
| lib/express.js | safe | No malicious patterns detected |
| lib/middleware/init.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/request.js | safe | This is the standard Express.js request prototype module with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
| lib/response.js | safe | The file is the standard Express.js response module with no malicious patterns, external exfiltration, credential harvesting, obfuscated payloads, or suspicious install-time behavior detected. |
| lib/router/index.js | safe | No malicious patterns detected; this is the standard Express.js router implementation with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| lib/router/layer.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/router/route.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/utils.js | safe | No malicious patterns detected; the code is the standard Express.js utility module with expected, benign functionality. |
Affected version ranges
None of the 3 scanned versions of express are flagged high or critical. The latest scanned version, 5.2.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 4.22.1 โ 5.2.1 | Needs review | 2 | >=4.22.1 <=5.2.1 | Prototype Pollution; Dynamic module loading with computed input |
| 4.21.2 | Not scanned | 1 | 4.21.2 | |
| 4.19.2 | Needs review | 1 | 4.19.2 | Prototype Pollution; Dynamic module loading with computed input |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of express
Frequently asked questions
Is express safe to use?
No confirmed malware was found in express@4.19.2, but the review flagged 1 high, 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does express contain malware?
No malware was identified in express@4.19.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was express checked?
Togoder Security downloaded the published npm package and had an AI model read its 12 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan express together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in express@4.19.2, cost nothing.