CVE-2026-33979 | AhmedAdelFahim express-xss-sanitizer up to 2.0.1 req.body/req.query/req.headers/req.params permissive list of allowed inputs (GHSA-3843-rr4g-m8jq)
A vulnerability was found in AhmedAdelFahim express-xss-sanitizer up to 2.0.1. It has been rated as critical. The impacted element is an unknown function. The manipulation of the argument req.body/req.query/req.headers/req.params leads to permissive list of allowed inputs.
This vulnerability is listed as CVE-2026-33979. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.