Fix qs vulnerability (GHSA-q8mj-m7cp-5q26)

Task: Fix medium-severity qs DoS vulnerability in the dependency chain.

The vulnerability affects qs >=6.11.1 <=6.15.1 — qs.stringify crashes
with a TypeError when null/undefined entries appear in comma-format arrays
with encodeValuesOnly set. The fix requires upgrading to qs >=6.15.2.

The affected path was: artifacts/api-server > express > qs@6.15.1

Fix: Added a pnpm workspace override in pnpm-workspace.yaml to force
qs to >=6.15.2 across all packages:

  qs: ">=6.15.2"

Ran `pnpm install` to apply the override (+1/-1 package). Confirmed with
`pnpm audit` — no known vulnerabilities found after the fix.

No code changes were required; only the lockfile and workspace config
were updated.

Replit-Task-Id: 59fbfd17-c5e4-4330-b97c-49a9e383db2e
This commit is contained in:
cheffe01
2026-05-25 13:10:23 +00:00
parent 036973ea32
commit e03c51a75e
2 changed files with 9 additions and 6 deletions
+6 -5
View File
@@ -152,6 +152,7 @@ overrides:
'@expo/ngrok-bin>@expo/ngrok-bin-win32-x64': '-' '@expo/ngrok-bin>@expo/ngrok-bin-win32-x64': '-'
'@esbuild-kit/esm-loader': npm:tsx@^4.21.0 '@esbuild-kit/esm-loader': npm:tsx@^4.21.0
esbuild: 0.27.3 esbuild: 0.27.3
qs: '>=6.15.2'
importers: importers:
@@ -2687,8 +2688,8 @@ packages:
resolution: {integrity: sha512-uxFIHU0YlHYhDQtV4R9J6a52SLx28BCjT+4ieh7IGbgwVJWO+km431c4yRlREUAsAmt/uMjQUyQHNEPf0M39CA==} resolution: {integrity: sha512-uxFIHU0YlHYhDQtV4R9J6a52SLx28BCjT+4ieh7IGbgwVJWO+km431c4yRlREUAsAmt/uMjQUyQHNEPf0M39CA==}
engines: {node: '>=6'} engines: {node: '>=6'}
qs@6.15.1: qs@6.15.2:
resolution: {integrity: sha512-6YHEFRL9mfgcAvql/XhwTvf5jKcOiiupt2FiJxHkiX1z4j7WL8J/jRHYLluORvc1XxB5rV20KoeK00gVJamspg==} resolution: {integrity: sha512-Rzq0KEyX/w/tEybncDgdkZrJgVUsUMk3xjh3t5bv3S1HTAtg+uOYt72+ZfwiQwKdysThkTBdL/rTi6HDmX9Ddw==}
engines: {node: '>=0.6'} engines: {node: '>=0.6'}
queue-microtask@1.2.3: queue-microtask@1.2.3:
@@ -4454,7 +4455,7 @@ snapshots:
http-errors: 2.0.1 http-errors: 2.0.1
iconv-lite: 0.7.2 iconv-lite: 0.7.2
on-finished: 2.4.1 on-finished: 2.4.1
qs: 6.15.1 qs: 6.15.2
raw-body: 3.0.2 raw-body: 3.0.2
type-is: 2.0.1 type-is: 2.0.1
transitivePeerDependencies: transitivePeerDependencies:
@@ -4741,7 +4742,7 @@ snapshots:
once: 1.4.0 once: 1.4.0
parseurl: 1.3.3 parseurl: 1.3.3
proxy-addr: 2.0.7 proxy-addr: 2.0.7
qs: 6.15.1 qs: 6.15.2
range-parser: 1.2.1 range-parser: 1.2.1
router: 2.2.0 router: 2.2.0
send: 1.2.1 send: 1.2.1
@@ -5265,7 +5266,7 @@ snapshots:
punycode.js@2.3.1: {} punycode.js@2.3.1: {}
qs@6.15.1: qs@6.15.2:
dependencies: dependencies:
side-channel: 1.1.0 side-channel: 1.1.0
+2
View File
@@ -158,3 +158,5 @@ overrides:
# drizzle-kit uses esbuild internally on an older version that's vulnerable, this overrides it # drizzle-kit uses esbuild internally on an older version that's vulnerable, this overrides it
"@esbuild-kit/esm-loader": "npm:tsx@^4.21.0" "@esbuild-kit/esm-loader": "npm:tsx@^4.21.0"
esbuild: "0.27.3" esbuild: "0.27.3"
# Fix GHSA-q8mj-m7cp-5q26: qs DoS via stringify with null/undefined in comma-format arrays
qs: ">=6.15.2"