Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions History.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
5.2.1 / 2025-12-01
=======================

* Revert security fix for [CVE-2024-51999](https://www.cve.org/CVERecord?id=CVE-2024-51999) ([GHSA-pj86-cfqh-vqx6](https://github.com/expressjs/express/security/advisories/GHSA-pj86-cfqh-vqx6))

5.2.0 / 2025-12-01
========================

Expand Down
2 changes: 1 addition & 1 deletion lib/utils.js
Original file line number Diff line number Diff line change
Expand Up @@ -266,6 +266,6 @@ function createETagGenerator (options) {

function parseExtendedQueryString(str) {
return qs.parse(str, {
plainObjects: true
allowPrototypes: true
});
}
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "express",
"description": "Fast, unopinionated, minimalist web framework",
"version": "5.2.0",
"version": "5.2.1",
"author": "TJ Holowaychuk <[email protected]>",
"contributors": [
"Aaron Heckmann <[email protected]>",
Expand Down
91 changes: 2 additions & 89 deletions test/req.query.js
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,6 @@
var assert = require('node:assert')
var express = require('../')
, request = require('supertest');
var qs = require('qs');

describe('req', function(){
describe('.query', function(){
Expand Down Expand Up @@ -39,22 +38,6 @@ describe('req', function(){
.get('/?user.name=tj')
.expect(200, '{"user.name":"tj"}', done);
});

it('should not be able to access object prototype properties', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?foo=yee')
.expect(200, /TypeError: req\.query\.hasOwnProperty is not a function/, done);
});

it('should be able to use object prototype property names as keys', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?hasOwnProperty=yee')
.expect(200, '{"query":{"hasOwnProperty":"yee"},"error":"TypeError: req.query.hasOwnProperty is not a function"}', done);
});
});

describe('when "query parser" is simple', function () {
Expand All @@ -65,22 +48,6 @@ describe('req', function(){
.get('/?user%5Bname%5D=tj')
.expect(200, '{"user[name]":"tj"}', done);
});

it('should not be able to access object prototype properties', function (done) {
var app = createApp('simple', true);

request(app)
.get('/?foo=yee')
.expect(200, /TypeError: req\.query\.hasOwnProperty is not a function/, done);
});

it('should be able to use object prototype property names as keys', function (done) {
var app = createApp('simple', true);

request(app)
.get('/?hasOwnProperty=yee')
.expect(200, '{"query":{"hasOwnProperty":"yee"},"error":"TypeError: req.query.hasOwnProperty is not a function"}', done);
});
});

describe('when "query parser" is a function', function () {
Expand All @@ -93,18 +60,6 @@ describe('req', function(){
.get('/?user%5Bname%5D=tj')
.expect(200, '{"length":17}', done);
});

// test exists to verify behavior for folks wishing to workaround our qs defaults
it('should drop object prototype property names and be able to access object prototype properties', function (done) {
var app = createApp(
function (str) {
return qs.parse(str)
}, true);

request(app)
.get('/?hasOwnProperty=biscuits')
.expect(200, '{"query":{},"hasOwnProperty":false}', done);
});
});

describe('when "query parser" disabled', function () {
Expand All @@ -115,22 +70,6 @@ describe('req', function(){
.get('/?user%5Bname%5D=tj')
.expect(200, '{}', done);
});

it('should not be able to access object prototype properties', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?foo=yee')
.expect(200, /TypeError: req\.query\.hasOwnProperty is not a function/, done);
});

it('should be able to use object prototype property names as keys', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?hasOwnProperty=yee')
.expect(200, '{"query":{"hasOwnProperty":"yee"},"error":"TypeError: req.query.hasOwnProperty is not a function"}', done);
});
});

describe('when "query parser" enabled', function () {
Expand All @@ -141,22 +80,6 @@ describe('req', function(){
.get('/?user%5Bname%5D=tj')
.expect(200, '{"user[name]":"tj"}', done);
});

it('should not be able to access object prototype properties', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?foo=yee')
.expect(200, /TypeError: req\.query\.hasOwnProperty is not a function/, done);
});

it('should be able to use object prototype property names as keys', function (done) {
var app = createApp('extended', true);

request(app)
.get('/?hasOwnProperty=yee')
.expect(200, '{"query":{"hasOwnProperty":"yee"},"error":"TypeError: req.query.hasOwnProperty is not a function"}', done);
});
});

describe('when "query parser" an unknown value', function () {
Expand All @@ -168,25 +91,15 @@ describe('req', function(){
})
})

function createApp(setting, isPrototypePropertyTest) {
function createApp(setting) {
var app = express();

if (setting !== undefined) {
app.set('query parser', setting);
}

app.use(function (req, res) {
if(isPrototypePropertyTest) {
try {
var hasOwnProperty = req.query.hasOwnProperty('✨ express ✨');
res.send({ query: req.query, hasOwnProperty: hasOwnProperty });
} catch (error) {
res.send({ query: req.query, error: error.toString() });
}
}
else {
res.send(req.query);
}
res.send(req.query);
});

return app;
Expand Down