MEDIUM
morgan
CVE published 2026-09-11
CVE-2026-87859
A vulnerability in the morgan HTTP request logger middleware for Node.js allows an unauthenticated remote attacker to inject malicious data into log files by exploiting the lack of double quote escaping in the escapeLogField() function. This issue, fixed in morgan 1.12.1, can lead to log tampering and potential security issues. Node.js developers and administrators should assess their exposure and upgrade [truncated]