Summary
Togoder Security scanned the npm package express@5.2.1 on Oct 4, 2026. An AI review of 7 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Potential prototype pollution
NPS-DB082120B298
parseExtendedQueryString calls qs.parse with allowPrototypes: true, which enables prototype pollution when parsing untrusted query strings. This is an intentional Express feature for extended query parsing but can be a security risk if user input is not validated.
Dynamic module loading
NPS-3B6E1A87976E
The code calls require(mod) where mod is derived from the file extension (this.ext.slice(1)) of a user-supplied view name. If an attacker can control the view name or extension, this could be used to load arbitrary modules, though in practice the extension is constrained by the default engine or the provided name. This is standard Express behavior but is a dynamic require based on computed input.
Path resolution from user input
NPS-8E2AFB86DC86
The lookup method resolves view paths using path.resolve(root, name) and then checks file existence with fs.statSync. While this is expected for a view engine, if the name is attacker-controlled, path traversal could potentially allow reading files outside the intended view directory (though resolve alone doesn't prevent traversal, but the file must match the expected extension and be a file). This is inherent to the Express view system and not inherently malicious.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/view.js | medium | The code is the standard Express View implementation; it contains dynamic require and path resolution from input, which are expected behaviors but could pose low risk if the view name is attacker-controlled. |
| index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/application.js | safe | No malicious patterns detected; this is the standard Express.js application module with legitimate framework code only. |
| lib/express.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/request.js | safe | No malicious patterns detected; this is a legitimate express request library handling standard HTTP request parsing and proxy trust configuration. |
| lib/response.js | safe | This is the standard Express.js response module with no malicious patterns, backdoors, or unauthorized network/file system access. |
| lib/utils.js | safe | The file contains standard Express utility functions with one medium-severity concern regarding allowPrototypes in qs.parse, but no malicious patterns, exfiltration, backdoors, or dynamic code execution. |
Affected version ranges
None of the 3 scanned versions of express are flagged high or critical. The latest scanned version, 5.2.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 4.22.1 โ 5.2.1 | Needs review | 2 | >=4.22.1 <=5.2.1 | Prototype Pollution; Dynamic module loading with computed input |
| 4.21.2 | Not scanned | 1 | 4.21.2 | |
| 4.19.2 | Needs review | 1 | 4.19.2 | Prototype Pollution; Dynamic module loading with computed input |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of express
Frequently asked questions
Is express safe to use?
No confirmed malware was found in express@5.2.1, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does express contain malware?
No malware was identified in express@5.2.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was express checked?
Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan express together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in express@5.2.1, cost nothing.