Togoder security

npm package security report

express@5.2.1 security report

Risky patterns found that deserve a look.

Needs review Version 5.2.1 Files reviewed 7 Size 60.1 KB Scanned

Summary

Togoder Security scanned the npm package express@5.2.1 on Oct 4, 2026. An AI review of 7 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
2
low

Findings 3

medium

Potential prototype pollution

NPS-DB082120B298

parseExtendedQueryString calls qs.parse with allowPrototypes: true, which enables prototype pollution when parsing untrusted query strings. This is an intentional Express feature for extended query parsing but can be a security risk if user input is not validated.

lib/utils.js:246
low

Dynamic module loading

NPS-3B6E1A87976E

The code calls require(mod) where mod is derived from the file extension (this.ext.slice(1)) of a user-supplied view name. If an attacker can control the view name or extension, this could be used to load arbitrary modules, though in practice the extension is constrained by the default engine or the provided name. This is standard Express behavior but is a dynamic require based on computed input.

lib/view.js:74
low

Path resolution from user input

NPS-8E2AFB86DC86

The lookup method resolves view paths using path.resolve(root, name) and then checks file existence with fs.statSync. While this is expected for a view engine, if the name is attacker-controlled, path traversal could potentially allow reading files outside the intended view directory (though resolve alone doesn't prevent traversal, but the file must match the expected extension and be a file). This is inherent to the Express view system and not inherently malicious.

lib/view.js:98

Files reviewed

FileVerdictWhat the reviewer saw
lib/view.js medium The code is the standard Express View implementation; it contains dynamic require and path resolution from input, which are expected behaviors but could pose low risk if the view name is attacker-controlled.
index.js safe Cleared by Jev triage; no further analysis needed
lib/application.js safe No malicious patterns detected; this is the standard Express.js application module with legitimate framework code only.
lib/express.js safe Cleared by Jev triage; no further analysis needed
lib/request.js safe No malicious patterns detected; this is a legitimate express request library handling standard HTTP request parsing and proxy trust configuration.
lib/response.js safe This is the standard Express.js response module with no malicious patterns, backdoors, or unauthorized network/file system access.
lib/utils.js safe The file contains standard Express utility functions with one medium-severity concern regarding allowPrototypes in qs.parse, but no malicious patterns, exfiltration, backdoors, or dynamic code execution.

Affected version ranges

None of the 3 scanned versions of express are flagged high or critical. The latest scanned version, 5.2.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

4.19.25.2.1
VersionsVerdictCountRangeTop findings
4.22.1 โ€“ 5.2.1 Needs review 2 >=4.22.1 <=5.2.1 Prototype Pollution; Dynamic module loading with computed input
4.21.2 Not scanned 1 4.21.2
4.19.2 Needs review 1 4.19.2 Prototype Pollution; Dynamic module loading with computed input

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of express

VersionVerdictFilesScanned
5.2.1 Needs review 7 Oct 4, 2026
4.22.1 Needs review 12 Oct 4, 2026
4.19.2 Needs review 12 Oct 4, 2026

Frequently asked questions

Is express safe to use?

No confirmed malware was found in express@5.2.1, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does express contain malware?

No malware was identified in express@5.2.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was express checked?

Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan express together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in express@5.2.1, cost nothing.

Related security reports