VDB
KO
HIGH 7.5

GHSA-rrrm-qjm4-v8hf

Inefficient Regular Expression Complexity in marked

Quick fix

GHSA-rrrm-qjm4-v8hf — marked: upgrade to the fixed version with the command below.

npm install marked@4.0.10

Details

### Impact

_What kind of vulnerability is it?_

Denial of service.

The regular expression `block.def` may cause catastrophic backtracking against some strings. PoC is the following.

```javascript import * as marked from "marked";

marked.parse(`[x]:${' '.repeat(1500)}x ${' '.repeat(1500)} x`); ```

_Who is impacted?_

Anyone who runs untrusted markdown through marked and does not use a worker with a time limit.

### Patches

_Has the problem been patched?_

Yes

_What versions should users upgrade to?_

4.0.10

### Workarounds

_Is there a way for users to fix or remediate the vulnerability without upgrading?_

Do not run untrusted markdown through marked or run marked on a [worker](https://marked.js.org/using_advanced#workers) thread and set a reasonable time limit to prevent draining resources.

### References

_Are there any links users can visit to find out more?_

- https://marked.js.org/using_advanced#workers - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS

### For more information

If you have any questions or comments about this advisory:

* Open an issue in [marked](https://github.com/markedjs/marked)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / marked
Introduced in: 0 Fixed in: 4.0.10
Fix npm install marked@4.0.10

References