Togoder security

npm package security report

express@4.19.2 security report

Risky patterns found that deserve a look.

Needs review Version 4.19.2 Files reviewed 12 Size 89.7 KB Scanned

Summary

Togoder Security scanned the npm package express@4.19.2 on Oct 4, 2026. An AI review of 12 source files produced 1 high, 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
1
high
2
medium
1
low

Findings 4

high

Prototype Pollution

NPS-639A5154F5E8

The code explicitly sets opts.allowPrototypes = true when options.allowPrototypes is undefined. This disables a security protection in the qs module that prevents properties like __proto__ and constructor from being parsed, allowing prototype pollution via query string parameters. An attacker can craft a query string such as ?__proto__[polluted]=yes to inject arbitrary properties into Object.prototype, potentially leading to denial of service, privilege escalation, or remote code execution depending on downstream usage.

lib/middleware/query.js:36
medium

Dynamic module loading with computed input

NPS-64DB8FE38166

The View constructor derives a module name from the file extension (this.ext.slice(1)) and passes it directly to require(mod). While this is standard Express behavior for loading view engines, if an attacker can control the extension or engine name (e.g., via user input that reaches defaultEngine or a view name with an attacker-controlled extension), it could allow loading of arbitrary installed modules. This is a known risk surface in Express and should be treated as a potential vector for module loading abuse.

lib/view.js:69
medium

File system path traversal potential

NPS-DE83FB5C067F

The lookup and resolve methods construct file paths by joining root with a user-supplied name using path.resolve/path.join. If name contains traversal sequences (e.g., ../), it could escape the intended view directory and resolve files outside the root. This is a classic directory traversal risk, though Express typically sanitizes view names at a higher level. The code itself does not enforce containment within root.

lib/view.js:96
low

Synchronous file system access

NPS-A24BED336A60

fs.statSync is used in tryStat to check file existence synchronously. While not malicious, synchronous I/O in a view resolution path can be abused for denial-of-service (blocking the event loop) if called with many crafted view names. This is a minor performance/security concern.

lib/view.js:149

Files reviewed

FileVerdictWhat the reviewer saw
lib/middleware/query.js medium The query middleware intentionally enables allowPrototypes for backwards compatibility, reintroducing a known prototype pollution vulnerability in the qs parser.
lib/view.js medium The code is the legitimate Express View module with no overt malicious patterns, but it contains inherent risks around dynamic module loading via file extension and potential path traversal in view lookup that could be abused if inputs are not properly sanitized upstream.
index.js safe Cleared by Jev triage; no further analysis needed
lib/application.js safe This is the standard Express.js application module (lib/application.js) with no malicious patterns; all requires, logic, and exports are consistent with the legitimate, widely-used express framework.
lib/express.js safe No malicious patterns detected
lib/middleware/init.js safe Cleared by Jev triage; no further analysis needed
lib/request.js safe This is the standard Express.js request prototype module with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
lib/response.js safe The file is the standard Express.js response module with no malicious patterns, external exfiltration, credential harvesting, obfuscated payloads, or suspicious install-time behavior detected.
lib/router/index.js safe No malicious patterns detected; this is the standard Express.js router implementation with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
lib/router/layer.js safe Cleared by Jev triage; no further analysis needed
lib/router/route.js safe Cleared by Jev triage; no further analysis needed
lib/utils.js safe No malicious patterns detected; the code is the standard Express.js utility module with expected, benign functionality.

Affected version ranges

None of the 3 scanned versions of express are flagged high or critical. The latest scanned version, 5.2.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

4.19.25.2.1
VersionsVerdictCountRangeTop findings
4.22.1 โ€“ 5.2.1 Needs review 2 >=4.22.1 <=5.2.1 Prototype Pollution; Dynamic module loading with computed input
4.21.2 Not scanned 1 4.21.2
4.19.2 Needs review 1 4.19.2 Prototype Pollution; Dynamic module loading with computed input

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of express

VersionVerdictFilesScanned
5.2.1 Needs review 7 Oct 4, 2026
4.22.1 Needs review 12 Oct 4, 2026
4.19.2 Needs review 12 Oct 4, 2026

Frequently asked questions

Is express safe to use?

No confirmed malware was found in express@4.19.2, but the review flagged 1 high, 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does express contain malware?

No malware was identified in express@4.19.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was express checked?

Togoder Security downloaded the published npm package and had an AI model read its 12 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan express together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in express@4.19.2, cost nothing.

Related security reports