{"id":2214303,"name":"query-string-parser","ecosystem":"npm","description":"Rack style query string parser for Node.js.","homepage":"https://github.com/victorteokw/query-parser","licenses":"MIT","normalized_licenses":["MIT"],"repository_url":"https://github.com/victorteokw/query-parser","keywords_array":["query","query string","url","search","rack","parameter"],"namespace":null,"versions_count":11,"first_release_published_at":"2015-08-07T12:47:10.232Z","latest_release_published_at":"2025-01-05T12:22:04.904Z","latest_release_number":"1.0.0","last_synced_at":"2026-05-23T01:13:00.888Z","created_at":"2022-04-09T22:35:42.370Z","updated_at":"2026-05-23T04:11:57.964Z","registry_url":"https://www.npmjs.com/package/query-string-parser","install_command":"npm install query-string-parser","documentation_url":null,"metadata":{"funding":null,"dist-tags":{"latest":"1.0.0"}},"repo_metadata":{"uuid":"40354324","full_name":"victorteokw/query-string-parser","owner":"victorteokw","description":"Rack style query string parser for Node.js","archived":false,"fork":false,"pushed_at":"2019-01-11T06:56:06.000Z","size":27,"stargazers_count":8,"open_issues_count":1,"forks_count":1,"subscribers_count":2,"default_branch":"master","last_synced_at":"2024-03-13T02:11:53.191Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/victorteokw.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2015-08-07T10:07:39.000Z","updated_at":"2022-07-27T07:04:34.000Z","dependencies_parsed_at":"2022-09-04T19:11:19.724Z","dependency_job_id":null,"html_url":"https://github.com/victorteokw/query-string-parser","commit_stats":null,"previous_names":["zhangkaiyulw/query-parser"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/victorteokw%2Fquery-string-parser","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/victorteokw%2Fquery-string-parser/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/victorteokw%2Fquery-string-parser/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/victorteokw%2Fquery-string-parser/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/victorteokw","download_url":"https://codeload.github.com/victorteokw/query-string-parser/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":196169322,"owners_count":13198672,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"victorteokw","name":"Victor Teo","uuid":"3055936","kind":"user","description":"Founder \u0026 CEO of Fillmula Inc.","email":"","website":null,"location":"Beijing, China","twitter":null,"company":"Fillmula Inc.","icon_url":"https://avatars.githubusercontent.com/u/3055936?u=594e027fb9f588086f1c4e868c858d3add3f8d45\u0026v=4","repositories_count":161,"last_synced_at":"2023-08-07T11:20:54.755Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/victorteokw","funding_links":[],"total_stars":null,"followers":null,"following":null,"created_at":"2022-11-06T19:20:44.926Z","updated_at":"2023-08-07T11:20:55.796Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/victorteokw","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/victorteokw/repositories"},"tags":[]},"repo_metadata_updated_at":"2026-05-23T01:13:21.139Z","dependent_packages_count":8,"downloads":1883,"downloads_period":"last-month","dependent_repos_count":8,"rankings":{"downloads":2.2180486930411303,"dependent_repos_count":4.074017406431603,"dependent_packages_count":2.4792591758145988,"stargazers_count":10.048574133139192,"forks_count":11.57520976212854,"docker_downloads_count":1.6254883929899413,"average":5.336766260590834},"purl":"pkg:npm/query-string-parser","advisories":[{"uuid":"GSA_kwCzR0hTQS01ODdwLXc0M3EtNGhqeM4ABWZY","url":"https://github.com/advisories/GHSA-587p-w43q-4hjx","title":"query-parser-string is vulnerable to Prototype Pollution","description":"NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2026-05-07T18:30:40.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2025-63704","https://github.com/victorteokw/query-string-parser/issues/3","https://gist.github.com/6en6ar/d62f614dbb2b1032b5e45a56fe26ec8b","https://www.npmjs.com/package/query-string-parser?activeTab=readme","https://github.com/advisories/GHSA-587p-w43q-4hjx"],"source_kind":"github","identifiers":["GHSA-587p-w43q-4hjx","CVE-2025-63704"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-12T17:00:08.790Z","updated_at":"2026-05-23T03:00:27.243Z","epss_percentage":0.0002,"epss_percentile":0.05961,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01ODdwLXc0M3EtNGhqeM4ABWZY","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01ODdwLXc0M3EtNGhqeM4ABWZY","packages":[{"ecosystem":"npm","package_name":"query-string-parser","versions":[{"first_patched_version":null,"vulnerable_version_range":"= 1.0.0"}],"purl":"pkg:npm/query-string-parser"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01ODdwLXc0M3EtNGhqeM4ABWZY/related_packages","related_advisories":[]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/npm/query-string-parser","docker_dependents_count":1,"docker_downloads_count":116,"usage_url":"https://repos.ecosyste.ms/usage/npm/query-string-parser","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/npm/query-string-parser/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":null,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/query-string-parser/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/query-string-parser/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/query-string-parser/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/query-string-parser/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/query-string-parser/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/query-string-parser/codemeta","maintainers":[{"uuid":"cheunghy","login":"cheunghy","name":null,"email":"yeannylam@gmail.com","url":null,"packages_count":144,"html_url":"https://www.npmjs.com/~cheunghy","role":null,"created_at":"2022-11-13T22:58:14.896Z","updated_at":"2022-11-13T22:58:14.896Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/cheunghy/packages"}]}