CVE-2025-59364: Express Xss Sanitizer Project Express Xss Sanitizer
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for Node.js has an unbounded recursion depth in sanitize in lib/sanitize.js for a JSON request body.
Affected products
- Express Xss Sanitizer Project Express Xss Sanitizer: version 2.0.0 only
Published 2025-09-14. Last modified 2026-06-17.