# express@5.2.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T14:40:43.000Z
- Files reviewed: 7
- Findings: 1 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/express@5.2.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package express@5.2.1 on Oct 4, 2026. An AI review of 7 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Potential prototype pollution

Finding ID: `NPS-DB082120B298`

File: `lib/utils.js:246`

parseExtendedQueryString calls qs.parse with allowPrototypes: true, which enables prototype pollution when parsing untrusted query strings. This is an intentional Express feature for extended query parsing but can be a security risk if user input is not validated.

### [low] Dynamic module loading

Finding ID: `NPS-3B6E1A87976E`

File: `lib/view.js:74`

The code calls require(mod) where mod is derived from the file extension (this.ext.slice(1)) of a user-supplied view name. If an attacker can control the view name or extension, this could be used to load arbitrary modules, though in practice the extension is constrained by the default engine or the provided name. This is standard Express behavior but is a dynamic require based on computed input.

### [low] Path resolution from user input

Finding ID: `NPS-8E2AFB86DC86`

File: `lib/view.js:98`

The lookup method resolves view paths using path.resolve(root, name) and then checks file existence with fs.statSync. While this is expected for a view engine, if the name is attacker-controlled, path traversal could potentially allow reading files outside the intended view directory (though resolve alone doesn't prevent traversal, but the file must match the expected extension and be a file). This is inherent to the Express view system and not inherently malicious.

## Files reviewed

- `lib/view.js` (medium): The code is the standard Express View implementation; it contains dynamic require and path resolution from input, which are expected behaviors but could pose low risk if the view name is attacker-controlled.
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/application.js` (safe): No malicious patterns detected; this is the standard Express.js application module with legitimate framework code only.
- `lib/express.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/request.js` (safe): No malicious patterns detected; this is a legitimate express request library handling standard HTTP request parsing and proxy trust configuration.
- `lib/response.js` (safe): This is the standard Express.js response module with no malicious patterns, backdoors, or unauthorized network/file system access.
- `lib/utils.js` (safe): The file contains standard Express utility functions with one medium-severity concern regarding allowPrototypes in qs.parse, but no malicious patterns, exfiltration, backdoors, or dynamic code execution.

## Version ranges

None of the 3 scanned versions of express are flagged high or critical. The latest scanned version, 5.2.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 4.22.1 – 5.2.1 (`>=4.22.1 <=5.2.1`): medium (Prototype Pollution +3 more)
- 4.21.2 (`4.21.2`): not scanned
- 4.19.2 (`4.19.2`): medium (Prototype Pollution +2 more)

## Scanned versions

- [5.2.1](https://security.togoder.click/npm/express@5.2.1): medium, 2026-10-04T14:40:43.000Z
- [4.22.1](https://security.togoder.click/npm/express@4.22.1): medium, 2026-10-04T16:30:53.000Z
- [4.19.2](https://security.togoder.click/npm/express@4.19.2): medium, 2026-10-04T16:51:35.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
