Description
morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan emits. An unauthenticated remote attacker who controls a value written to a quoted field, such as the User-Agent or Referer header, can include a double quote to close that field early, so a log consumer that parses the log by field position reads attacker-supplied text as the following field. In the built-in formats this makes the recorded value differ from the value that was sent, and in custom formats that quote an attacker-controlled token before a server-controlled one it can forge values such as the response status. No newline is injected, so record separation stays intact. The issue is fixed in morgan 1.12.1, which escapes the double quote. Users should upgrade to morgan 1.12.1 or later.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Log injection via unescaped double quote
Action: Patch
AI Analysis

Impact

The vulnerability is located in the escapeLogField() routine does not escape the double quote character, which is the delimiter used by the Apache combined log format. An unauthenticated attacker who can control a header that morgan records, such as User‑Agent or Referer, can insert a double quote to prematurely terminate the quoted field. The following field in the log is then interpreted as attacker‑supplied data. In standard format logs this rewrites the recorded value, and in custom formats that quote an attacker‑controlled token before a server‑controlled one it can forge entries such as, so individual log records remain distinct, but the integrity and trustworthiness of the logged data are undermined.

Affected Systems

Affected systems: The issue affects the morgan middleware for Node.js. All releases prior to version 1.12.1 are vulnerable. The vendor product is in version 1.12.1 and later.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, reflecting the primary damage of corrupting forensic log data rather than enabling direct compromise or denial of service. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, implying limited exploitation data. The attack vector requires only the ability to send crafted HTTP headers; thus an unauthenticated remote attacker can exploit it by sending a request with a forged User‑Agent or Referer field. The resulting distortion of log information can hamper incident response, auditing, and forensic investigations.

Generated by OpenCVE AI on September 11, 2026 at 11:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade morgan to version 1.12.1 or later
  • If an immediate upgrade is not possible, intercept incoming header values and strip or escape any double quote characters before they reach the logger
  • Consider disabling or removing logging of headers that can contain user‑controlled data until the patch is applied

Generated by OpenCVE AI on September 11, 2026 at 11:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9f6g-j8ch-79g4 morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 11 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Morgan
Morgan morgan
Vendors & Products Morgan
Morgan morgan

Fri, 11 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan emits. An unauthenticated remote attacker who controls a value written to a quoted field, such as the User-Agent or Referer header, can include a double quote to close that field early, so a log consumer that parses the log by field position reads attacker-supplied text as the following field. In the built-in formats this makes the recorded value differ from the value that was sent, and in custom formats that quote an attacker-controlled token before a server-controlled one it can forge values such as the response status. No newline is injected, so record separation stays intact. The issue is fixed in morgan 1.12.1, which escapes the double quote. Users should upgrade to morgan 1.12.1 or later.
Title morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
Weaknesses CWE-117
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-09-11T11:32:10.246Z

Reserved: 2026-09-09T13:05:45.895Z

Link: CVE-2026-87859

cve-icon Vulnrichment

Updated: 2026-09-11T11:32:06.132Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T10:16:53.253

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-87859

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T09:15:19Z

Links: CVE-2026-87859 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T15:45:16Z

Weaknesses
  • CWE-117

    Improper Output Neutralization for Logs