Skip to content

fix: qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion#16886

Merged
FelixMalfait merged 2 commits intomainfrom
dependabot-355
Jan 7, 2026
Merged

fix: qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion#16886
FelixMalfait merged 2 commits intomainfrom
dependabot-355

Conversation

@mabdullahabaid
Copy link
Copy Markdown
Member

Resolves Dependabot Alert 354 and Dependabot Alert 355.

Upgraded express by one minor version. Removed redundant type definition in root package.json since we already have it in twenty-server's package.json.

Upgraded body-parser patch version in serverless package.json.

Copy link
Copy Markdown
Contributor

@greptile-apps greptile-apps bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.

Copy link
Copy Markdown
Contributor

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 5 files

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Dec 31, 2025

🚀 Preview Environment Ready!

Your preview environment is available at: http://bore.pub:41128

This environment will automatically shut down when the PR is closed or after 5 hours.

@FelixMalfait FelixMalfait enabled auto-merge January 7, 2026 15:46
@FelixMalfait FelixMalfait added this pull request to the merge queue Jan 7, 2026
Merged via the queue into main with commit e83e616 Jan 7, 2026
74 checks passed
@FelixMalfait FelixMalfait deleted the dependabot-355 branch January 7, 2026 16:09
@twenty-eng-sync
Copy link
Copy Markdown

Hey @mabdullahabaid! After you've done the QA of your Pull Request, you can mark it as done here. Thank you!

1 similar comment
@twenty-eng-sync
Copy link
Copy Markdown

Hey @mabdullahabaid! After you've done the QA of your Pull Request, you can mark it as done here. Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants