[BUG] simple-rest 使用易受攻击的 decode-uri-component 版本
作者: harshmaur创建于 2026年9月11日更新于 2026年9月11日
描述错误 @refinedev/[email protected] 依赖于 query-string@^7.1.1,该依赖解析为 [email protected],并拉取了 decode-uri-component@^0.2.2。在 0.5.0 之前的 decode-uri-component 版本受到 CVE-2026-45822 / GHSA-vcc3-ghjq-m6fr 的影响,这是在解码不正确的百分比编码输入时的拒绝服务漏洞。
内容来源: refinedev/refine