Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

qs dependency locked to vulnerable version (< 6.14.1) #7619

Copy link
Copy link
@abhilashknair

Description

@abhilashknair
Issue body actions

Is there an existing issue for this?

  • I have searched the existing issues

OS/Web Information

Vulnerable qs dependency (< 6.14.1)

A security vulnerability has been reported in the qs package affecting versions earlier than 6.14.1:

In code-server, the qs dependency is currently locked to version 6.4.0:

This version appears to fall within the affected range described in the advisory.

Expected behavior

Upgrade qs to version 6.14.1 or later, or otherwise mitigate the reported vulnerability.

Steps to Reproduce

Expected

Upgrade qs to version 6.14.1 or later, or otherwise mitigate the reported vulnerability.

Actual

qs dependency is currently locked to version 6.4.0:

Logs

Screenshot/Video

No response

Does this bug reproduce in native VS Code?

Yes, this is also broken in native VS Code

Does this bug reproduce in VS Code web?

Yes, this is also broken in VS Code web

Does this bug reproduce in GitHub Codespaces?

Yes, this is also broken in GitHub Codespaces

Are you accessing code-server over a secure context?

  • I am using a secure context.

Notes

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingSomething isn't workingsecuritySecurity relatedSecurity relatedtriageThis issue needs to be triaged by a maintainerThis issue needs to be triaged by a maintainer

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      Morty Proxy This is a proxified and sanitized view of the page, visit original site.