Describe the bug
@refinedev/simple-rest@6.0.1 depends on query-string@^7.1.1, which resolves to query-string@7.1.3 and pulls decode-uri-component@^0.2.2. Versions of decode-uri-component before 0.5.0 are affected by CVE-2026-45822 / GHSA-vcc3-ghjq-m6fr, a denial-of-service vulnerability when decoding malformed percent-encoded input.
The current secure query-string release uses decode-uri-component@^0.5.0, but it is ESM-only. Any upgrade must preserve the ESM and CommonJS exports promised by @refinedev/simple-rest.
Steps To Reproduce
- Install
@refinedev/simple-rest@6.0.1.
- Inspect the installed dependency graph.
- Observe
@refinedev/simple-rest -> query-string@7.1.3 -> decode-uri-component@0.2.2.
- Run a vulnerability scanner that includes GHSA-vcc3-ghjq-m6fr.
Expected behavior
@refinedev/simple-rest must not install a vulnerable decode-uri-component release, and its ESM and CommonJS package exports must continue to work.
Packages
@refinedev/simple-rest@6.0.1
query-string@7.1.3
decode-uri-component@0.2.2
Additional Context
Advisory: GHSA-vcc3-ghjq-m6fr
The fixed decode-uri-component@0.5.0 release is ESM-only, so a direct transitive override breaks CommonJS consumers of query-string@7.
Describe the bug
@refinedev/simple-rest@6.0.1depends onquery-string@^7.1.1, which resolves toquery-string@7.1.3and pullsdecode-uri-component@^0.2.2. Versions ofdecode-uri-componentbefore 0.5.0 are affected by CVE-2026-45822 / GHSA-vcc3-ghjq-m6fr, a denial-of-service vulnerability when decoding malformed percent-encoded input.The current secure
query-stringrelease usesdecode-uri-component@^0.5.0, but it is ESM-only. Any upgrade must preserve the ESM and CommonJS exports promised by@refinedev/simple-rest.Steps To Reproduce
@refinedev/simple-rest@6.0.1.@refinedev/simple-rest -> query-string@7.1.3 -> decode-uri-component@0.2.2.Expected behavior
@refinedev/simple-restmust not install a vulnerabledecode-uri-componentrelease, and its ESM and CommonJS package exports must continue to work.Packages
@refinedev/simple-rest@6.0.1query-string@7.1.3decode-uri-component@0.2.2Additional Context
Advisory: GHSA-vcc3-ghjq-m6fr
The fixed
decode-uri-component@0.5.0release is ESM-only, so a direct transitive override breaks CommonJS consumers ofquery-string@7.