Description
### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: -comma-` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs-s null-related options (`skipNulls`, `strictNullHandling`). ### Details In the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining: ```js obj = utils.maybeMap(obj, encoder); ``` `utils.encode` (`lib/utils.js:195`) reads `str.length` with no null guard, so a `null` or `undefined` element throws `TypeError`. `skipNulls` and `strictNullHandling` are both checked in the per-element loop below this line and never get a chance to run. Same class of bug as the filter-array path fixed in 0c180a4. The vulnerable shape of the comma + `encodeValuesOnly` branch was introduced in 4c4b23d (-encode comma values more consistently-, PR #463, 2023-01-19), first released in v6.11.1. #### PoC ```js const qs = require(-qs-); qs.string...
- Publication
- 2026-05-17 00:16:21
- Versions concernées
- >=6.11.1,<6.12.0
- Type
- Package
- Vecteur
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L