HIGH7.5
GHSA-7f3x-2wcx-hww8
steal vulnerable to Regular Expression Denial of Service via input variable
Details
A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal via the input variable in main.js.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/steal
Introduced in:
0No fixed version published yet for steal (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-37260[ADVISORY]
- https://github.com/stealjs/steal/issues/1529[WEB]
- https://github.com/stealjs/steal[PACKAGE]
- https://github.com/stealjs/steal/blob/c9dd1eb19ed3f97aeb93cf9dcea5d68ad5d0ced9/main.js#L2490[WEB]
- https://github.com/stealjs/steal/blob/c9dd1eb19ed3f97aeb93cf9dcea5d68ad5d0ced9/main.js#L3344[WEB]