Frourio is a TypeScript-based web framework and tooling suite for building type-safe REST APIs, with its vulnerability footprint concentrated in the core framework and Express integration products. The observed disclosures center on input-validation and prototype-pollution weaknesses, reflecting the attack surface inherent to a JavaScript runtime framework that processes HTTP requests and object serialization. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frourio over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23624HIGH Frourio-express is a minimal full stack framework, for TypeScript. Frourio-express users who uses frourio-express version prior to v0.26.0 and integration with class-validator thro | Feb 7, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-23623HIGH Frourio is a full stack framework, for TypeScript. Frourio users who uses frourio version prior to v0.26.0 and integration with class-validator through `validators/` folder are sub | Feb 7, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frourio.
Media articles that mention a CVE ID that affects a product developed by Frourio — matched by CVE ID, not by vendor name.