VYPR
Medium severity4.0NVD Advisory· Published Oct 29, 2024· Updated Jun 17, 2026

CVE-2024-10491

CVE-2024-10491

Description

A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used.

The issue arises from improper sanitization in Link header values, which can allow a combination of characters like ,, ;, and <> to preload malicious resources.

This vulnerability is especially relevant for dynamic parameters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
expressnpm
< 4.0.0-rc14.0.0-rc1

Affected products

10

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.