Skip to content

chore(deps): bump qs to 6.15.2 (CVE-2026-8723)#42

Merged
LanNguyenSi merged 1 commit into
masterfrom
chore/cve-sweep-qs-6.15.2
May 25, 2026
Merged

chore(deps): bump qs to 6.15.2 (CVE-2026-8723)#42
LanNguyenSi merged 1 commit into
masterfrom
chore/cve-sweep-qs-6.15.2

Conversation

@LanNguyenSi
Copy link
Copy Markdown
Owner

Resolves Dependabot alert (qs DoS). Lockfile-only.

Resolves Dependabot alert (medium): qs <=6.15.1 has a remotely
triggerable DoS where qs.stringify crashes with TypeError on
null/undefined entries in comma-format arrays when encodeValuesOnly
is set.

Lockfile-only change; qs is transitive.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@LanNguyenSi LanNguyenSi merged commit 7e10af4 into master May 25, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants