Skip to content

[BUG] simple-rest pulls vulnerable decode-uri-component version #7601

Description

@harshmaur

Describe the bug

@refinedev/simple-rest@6.0.1 depends on query-string@^7.1.1, which resolves to query-string@7.1.3 and pulls decode-uri-component@^0.2.2. Versions of decode-uri-component before 0.5.0 are affected by CVE-2026-45822 / GHSA-vcc3-ghjq-m6fr, a denial-of-service vulnerability when decoding malformed percent-encoded input.

The current secure query-string release uses decode-uri-component@^0.5.0, but it is ESM-only. Any upgrade must preserve the ESM and CommonJS exports promised by @refinedev/simple-rest.

Steps To Reproduce

  1. Install @refinedev/simple-rest@6.0.1.
  2. Inspect the installed dependency graph.
  3. Observe @refinedev/simple-rest -> query-string@7.1.3 -> decode-uri-component@0.2.2.
  4. Run a vulnerability scanner that includes GHSA-vcc3-ghjq-m6fr.

Expected behavior

@refinedev/simple-rest must not install a vulnerable decode-uri-component release, and its ESM and CommonJS package exports must continue to work.

Packages

  • @refinedev/simple-rest@6.0.1
  • query-string@7.1.3
  • decode-uri-component@0.2.2

Additional Context

Advisory: GHSA-vcc3-ghjq-m6fr

The fixed decode-uri-component@0.5.0 release is ESM-only, so a direct transitive override breaks CommonJS consumers of query-string@7.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions