CVE-2025-15284 tracked by snyk here https://security.snyk.io/vuln/SNYK-JS-QS-14724253
Please update the library to use a version that does not have the above vulnerability.
Note: Since the package.json uses tilde qs": "~6.9.1 this cannot automatically be addressed. I am using overrides on my end right now to workaround it.