-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The commit diff shows critical modifications to the getValue function in fetchParams.js, specifically adding array handling to mitigate parameter pollution. The patch explicitly states it 'protects against HTTP Parameter Pollution attacks' and the CWE-235 classification matches this parameter handling flaw. The function's pre-patch behavior of returning raw parameter values without array sanitization directly enabled the vulnerability.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| express-param | npm | < 1.0.0 | 1.0.0 |
Ongoing coverage of React2Shell