# Security Notes

## Known Vulnerabilities

### `express-formidable@1.2.0`
- **Issue**: This package has a known Prototype Pollution vulnerability.
- **Why it's used**: It is currently required by `@adminjs/express` for handling file uploads in the AdminJS dashboard.
- **Action Required**: 
  - Do not use `express-formidable` for any new endpoints.
  - Monitor `@adminjs/express` for updates. If they migrate to `multer` or update their dependency, upgrade `@adminjs/express` immediately.
  - Alternatively, if customizing the AdminJS upload provider, consider writing a custom adapter that uses `multer` instead of relying on `express-formidable`.
