Elysiajs Elysia vulnerabilities
4 known vulnerabilities affecting elysiajs/elysia.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-31865MEDIUMCVSS 5.3fixed in 1.4.272026-03-18
CVE-2026-31865 [MEDIUM] CWE-1321 CVE-2026-31865: Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to version 1.4.27, an Elysia cookie can be overridden by prototype pollution , eg. `__proto__`. This issue is patched in 1.4.27. As a workaround, use t.Cookie validation to enforce validation value and/or prevent ite
cvelistv5ghsanvdosv
CVE-2026-30837HIGHCVSS 7.5fixed in 1.4.262026-03-10
CVE-2026-30837 [HIGH] CWE-1333 CVE-2026-30837: Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and c
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Prior to 1.4.26 , t.String({ format: 'url' }) is vulnerable to ReDoS. Repeating a partial url format (protocol and hostname) multiple times cause regex to slow down significantly. This vulnerability is fixed in 1.4.26.
cvelistv5ghsanvdosv
CVE-2025-66456CRITICALCVSS 9.1≥ 1.4.0, < 1.4.17v>= 1.4.0, < 1.4.172025-12-09
CVE-2025-66456 [CRITICAL] CWE-1321 CVE-2025-66456: Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and c
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.0 through 1.4.16 contain a prototype pollution vulnerability in `mergeDeep` after merging results of two standard schema validations with the same key. Due to the ordering of merging, there must be an any ty
cvelistv5ghsanvdosv
CVE-2025-66457HIGHCVSS 7.5fixed in 1.4.182025-12-09
CVE-2025-66457 [HIGH] CWE-94 CVE-2025-66457: Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and c
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.17 and below are subject to arbitrary code execution from cookie config. When dynamic cookies are enabled (e.g. there an existing cookie schema), the cookie config is injected into the compiled route without first
cvelistv5ghsanvdosv