Loading npm security reports…
This document describes the management of vulnerabilities for the project and all modules within the organization.
Runtime use of the exported middleware fetches attacker-controlled JavaScript and executes it in the host Node process. This is remote code execution, not a legitimate express/chai feature.
Source passes code obtained from a remote response into a dynamic execution sink.
lib/caller.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/caller.jsView on unpkgSource passes code obtained from a remote response into a dynamic execution sink.
lib/caller.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/caller.jsView on unpkg