Impact
The vulnerability is located in the escapeLogField() routine does not escape the double quote character, which is the delimiter used by the Apache combined log format. An unauthenticated attacker who can control a header that morgan records, such as User‑Agent or Referer, can insert a double quote to prematurely terminate the quoted field. The following field in the log is then interpreted as attacker‑supplied data. In standard format logs this rewrites the recorded value, and in custom formats that quote an attacker‑controlled token before a server‑controlled one it can forge entries such as, so individual log records remain distinct, but the integrity and trustworthiness of the logged data are undermined.
Affected Systems
Affected systems: The issue affects the morgan middleware for Node.js. All releases prior to version 1.12.1 are vulnerable. The vendor product is in version 1.12.1 and later.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, reflecting the primary damage of corrupting forensic log data rather than enabling direct compromise or denial of service. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, implying limited exploitation data. The attack vector requires only the ability to send crafted HTTP headers; thus an unauthenticated remote attacker can exploit it by sending a request with a forged User‑Agent or Referer field. The resulting distortion of log information can hamper incident response, auditing, and forensic investigations.
OpenCVE Enrichment
Github GHSA