It was discovered that Express incorrectly handled certain URLs, leading to an open redirect attack. A remote attacker could possibly use this issue to perform phishing attacks. (CVE-2024-29041)
Adam Korcz discovered that Express did not properly sanitize certain inputs. A remote attacker could possibly use this issue to perform cross site scripting. (CVE-2024-43796)