fix(security): update qs package to fix vulnerability CVE-2025-15284 (#5686)

fixes: qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion
This commit is contained in:
Joe Boccanfuso authored and GitHub committed 2026-01-05 12:23:34 -05:00
1 parent 50f6b52bbd
commit ca364a3af7
5 files changed
+175 -181

No files matched your search

+3
View File
@@ -95,5 +95,8 @@
"tailwindcss-animate": "1.0.7",
"typescript": "5.5.4",
"url-loader": "4.1.1"
},
"resolutions": {
"qs": "6.14.1"
}
}
+6 -6
View File
@@ -10202,12 +10202,12 @@ pupa@^3.1.0:
dependencies:
escape-goat "^4.0.0"
qs@6.13.0:
version "6.13.0"
resolved "https://registry.yarnpkg.com/qs/-/qs-6.13.0.tgz#6ca3bd58439f7e245655798997787b0d88a51906"
integrity sha512-+38qI9SOr8tfZ4QmJNplMUxqjbe7LKvvZgWdExBOmd+egZTtjLB67Gu0HRX3u/XOq7UU2Nx6nsjvS16Z9uwfpg==
qs@6.13.0, qs@6.14.1:
version "6.14.1"
resolved "https://registry.yarnpkg.com/qs/-/qs-6.14.1.tgz#a41d85b9d3902f31d27861790506294881871159"
integrity sha512-4EK3+xJl8Ts67nLYNwqw/dsFVnCf+qR7RgXSK9jEEm9unao3njwMDdmsdvoKBKHzxd7tCYz5e5M+SnMjdtXGQQ==
dependencies:
side-channel "^1.0.6"
side-channel "^1.1.0"
queue-microtask@^1.2.2:
version "1.2.3"
@@ -11209,7 +11209,7 @@ side-channel-weakmap@^1.0.2:
object-inspect "^1.13.3"
side-channel-map "^1.0.1"
side-channel@^1.0.6, side-channel@^1.1.0:
side-channel@^1.1.0:
version "1.1.0"
resolved "https://registry.yarnpkg.com/side-channel/-/side-channel-1.1.0.tgz#c3fcff9c4da932784873335ec9765fa94ff66bc9"
integrity sha512-ZX99e6tRweoUXqR+VBrslhda51Nh5MTQwou5tnUDgbtyM0dBgmhEDtWGP/xbKn6hqfPRHujUNwz5fy/wbbhnpw==