# express@4.19.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:51:35.000Z
- Files reviewed: 12
- Findings: 1 high, 2 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/express@4.19.2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package express@4.19.2 on Oct 4, 2026. An AI review of 12 source files produced 1 high, 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Prototype Pollution

Finding ID: `NPS-639A5154F5E8`

File: `lib/middleware/query.js:36`

The code explicitly sets `opts.allowPrototypes = true` when `options.allowPrototypes` is undefined. This disables a security protection in the `qs` module that prevents properties like `__proto__` and `constructor` from being parsed, allowing prototype pollution via query string parameters. An attacker can craft a query string such as `?__proto__[polluted]=yes` to inject arbitrary properties into Object.prototype, potentially leading to denial of service, privilege escalation, or remote code execution depending on downstream usage.

### [medium] Dynamic module loading with computed input

Finding ID: `NPS-64DB8FE38166`

File: `lib/view.js:69`

The View constructor derives a module name from the file extension (`this.ext.slice(1)`) and passes it directly to `require(mod)`. While this is standard Express behavior for loading view engines, if an attacker can control the extension or engine name (e.g., via user input that reaches `defaultEngine` or a view name with an attacker-controlled extension), it could allow loading of arbitrary installed modules. This is a known risk surface in Express and should be treated as a potential vector for module loading abuse.

### [medium] File system path traversal potential

Finding ID: `NPS-DE83FB5C067F`

File: `lib/view.js:96`

The `lookup` and `resolve` methods construct file paths by joining `root` with a user-supplied `name` using `path.resolve`/`path.join`. If `name` contains traversal sequences (e.g., `../`), it could escape the intended view directory and resolve files outside the root. This is a classic directory traversal risk, though Express typically sanitizes view names at a higher level. The code itself does not enforce containment within `root`.

### [low] Synchronous file system access

Finding ID: `NPS-A24BED336A60`

File: `lib/view.js:149`

`fs.statSync` is used in `tryStat` to check file existence synchronously. While not malicious, synchronous I/O in a view resolution path can be abused for denial-of-service (blocking the event loop) if called with many crafted view names. This is a minor performance/security concern.

## Files reviewed

- `lib/middleware/query.js` (medium): The `query` middleware intentionally enables `allowPrototypes` for backwards compatibility, reintroducing a known prototype pollution vulnerability in the `qs` parser.
- `lib/view.js` (medium): The code is the legitimate Express View module with no overt malicious patterns, but it contains inherent risks around dynamic module loading via file extension and potential path traversal in view lookup that could be abused if inputs are not properly sanitized upstream.
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/application.js` (safe): This is the standard Express.js application module (lib/application.js) with no malicious patterns; all requires, logic, and exports are consistent with the legitimate, widely-used express framework.
- `lib/express.js` (safe): No malicious patterns detected
- `lib/middleware/init.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/request.js` (safe): This is the standard Express.js request prototype module with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
- `lib/response.js` (safe): The file is the standard Express.js response module with no malicious patterns, external exfiltration, credential harvesting, obfuscated payloads, or suspicious install-time behavior detected.
- `lib/router/index.js` (safe): No malicious patterns detected; this is the standard Express.js router implementation with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
- `lib/router/layer.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/router/route.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/utils.js` (safe): No malicious patterns detected; the code is the standard Express.js utility module with expected, benign functionality.

## Version ranges

None of the 3 scanned versions of express are flagged high or critical. The latest scanned version, 5.2.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 4.22.1 – 5.2.1 (`>=4.22.1 <=5.2.1`): medium (Prototype Pollution +3 more)
- 4.21.2 (`4.21.2`): not scanned
- 4.19.2 (`4.19.2`): medium (Prototype Pollution +2 more)

## Scanned versions

- [5.2.1](https://security.togoder.click/npm/express@5.2.1): medium, 2026-10-04T14:40:43.000Z
- [4.22.1](https://security.togoder.click/npm/express@4.22.1): medium, 2026-10-04T16:30:53.000Z
- [4.19.2](https://security.togoder.click/npm/express@4.19.2): medium, 2026-10-04T16:51:35.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
