CVE-2025-59364: Express Xss Sanitizer Project Express Xss Sanitizer

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for Node.js has an unbounded recursion depth in sanitize in lib/sanitize.js for a JSON request body.

Affected products

Published 2025-09-14. Last modified 2026-06-17.