VDB
Sign up
HIGH7.5

GHSA-7f3x-2wcx-hww8

steal vulnerable to Regular Expression Denial of Service via input variable

Details

A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal via the input variable in main.js.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/steal
Introduced in: 0

No fixed version published yet for steal (npm). Pin to a known-safe version or switch to an alternative.

References