VDB
Sign up
HIGH7.5

GHSA-832h-xg76-4gv6

ReDoS in brace-expansion

Quick fix

GHSA-832h-xg76-4gv6 — brace-expansion: upgrade to the fixed version with the command below.

npm install brace-expansion@1.1.7

Details

Affected versions of `brace-expansion` are vulnerable to a regular expression denial of service condition.

## Proof of Concept

``` var expand = require('brace-expansion'); expand('{,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,\n}'); ```

## Recommendation

Update to version 1.1.7 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/brace-expansion
Introduced in: 0Fixed in: 1.1.7
Fixnpm install brace-expansion@1.1.7

References