# qs@6.14.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:39:45.000Z
- Files reviewed: 6
- Findings: 1 medium severity finding
- Report: https://security.togoder.click/npm/qs@6.14.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package qs@6.14.0 on Oct 4, 2026. An AI review of 6 source files produced 1 medium severity finding. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Prototype pollution

Finding ID: `NPS-AB498894CF85`

File: `lib/utils.js:133`

The merge function recursively merges source object properties into a target object. When options.plainObjects or options.allowPrototypes is not used, __proto__, constructor, or prototype keys passed in source may be merged into target and potentially alter Object.prototype behavior in consuming applications. This is a known security-sensitive pattern in qs/querystring-like utility code.

## Files reviewed

- `lib/utils.js` (medium): No obvious malicious behavior, but the merge utility has prototype pollution risk that should be assessed in the context of how callers sanitize input.
- `dist/qs.js` (safe): No malicious patterns detected; the code is a legitimate bundled copy of the qs library with no exfiltration, credential harvesting, obfuscated payloads, or suspicious behavior.
- `lib/formats.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/parse.js` (safe): No malicious patterns detected; this is the standard qs query string parser implementation.
- `lib/stringify.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 3 scanned versions of qs are flagged high or critical. The latest scanned version, 6.16.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 6.16.0 (`6.16.0`): clean
- 6.14.0 (`6.14.0`): medium (Prototype pollution)
- 6.13.0 (`6.13.0`): not scanned
- 6.11.0 (`6.11.0`): clean

## Scanned versions

- [6.16.0](https://security.togoder.click/npm/qs@6.16.0): safe, 2026-10-04T14:40:45.000Z
- [6.14.0](https://security.togoder.click/npm/qs@6.14.0): medium, 2026-10-04T16:39:45.000Z
- [6.11.0](https://security.togoder.click/npm/qs@6.11.0): safe, 2026-10-04T16:51:34.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
