It's important to increase the version of the @koa/cors package to
5.0
where the security issue is solved. See https://www.cve.org/CVERecord?id=CVE-2023-49803