qrcode uses an outdated version or yargs with a vulnerable transitive dependency
Author: davidsyckleCreated Sep 10, 2024Updated Mar 18, 2025
qrcode uses a direct dependency ("yargs": "^15.3.1") that pulls in a vulnerable component ([email protected]). Please update yargs to 17.0.2 or newer to remediate this issue. :)
Source: soldair/node-qrcode