VDB
Sign up
MEDIUM5.9

GHSA-9v62-24cr-58cx

Denial of Service in node-sass

Quick fix

GHSA-9v62-24cr-58cx — node-sass: upgrade to the fixed version with the command below.

npm install node-sass@4.13.1

Details

Affected versions of `node-sass` are vulnerable to Denial of Service (DoS). Crafted objects passed to the `renderSync` function may trigger C++ assertions in `CustomImporterBridge::get_importer_entry` and `CustomImporterBridge::post_process_return_value` that crash the Node process. This may allow attackers to crash the system's running Node process and lead to Denial of Service.

## Recommendation

Upgrade to version 4.13.1 or later

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/node-sass
Introduced in: 3.3.0Fixed in: 4.13.1
Fixnpm install node-sass@4.13.1

References