High severity8.1NVD Advisory· Published Feb 7, 2022· Updated Jun 17, 2026
CVE-2022-23624
CVE-2022-23624
Description
Frourio-express is a minimal full stack framework, for TypeScript. Frourio-express users who uses frourio-express version prior to v0.26.0 and integration with class-validator through validators/ folder are subject to a input validation vulnerability. Validators do not work properly for request bodies and queries in specific situations and some input is not validated at all. Users are advised to update frourio to v0.26.0 or later and to install class-transformer and reflect-metadata.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
frourio-expressnpm | < 0.26.0 | 0.26.0 |
Affected products
3- frouriojs/frourio-expressv5Range: < 0.26.0
Patches
Vulnerability mechanics
References
4- github.com/frouriojs/frourio-express/commit/73ded5c6f9f1c126c0cb2d05c0505e9e4db142d2nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-mmj4-777p-fpq9ghsaADVISORY
- github.com/frouriojs/frourio-express/security/advisories/GHSA-mmj4-777p-fpq9nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-23624ghsaADVISORY
News mentions
0No linked articles in our index yet.