Home

Description

The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for Node.js has an unbounded recursion depth in sanitize in lib/sanitize.js for a JSON request body.

PUBLISHED Reserved 2025-09-14 | Published 2025-09-14 | Updated 2025-09-15 | Assigner mitre




MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Problem types

CWE-674 Uncontrolled Recursion

Product status

Default status
unknown

2.0.0 (semver)
affected

References

github.com/AhmedAdelFahim/express-xss-sanitizer

www.npmjs.com/package/express-xss-sanitizer

gist.github.com/Spendroslav/177804eaef5acfb222a550de212a1b94

cve.org (CVE-2025-59364)

nvd.nist.gov (CVE-2025-59364)

Download JSON