Describe the bug
The package qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion: GHSA-6rw7-vpxm-498p.
To Reproduce
Run the following:
pnpm audit
The issue is the version of supertest you are using. If you update supertest to the latest version (v7.2.2), it contains the updated version of superagent, which has the patched version of qs.
Expected behavior
Vulnerable package is updated to patched version and vulnerability no longer exists.