VDB
Sign up
LOW

GHSA-ch52-vgq2-943f

Regular Expression Denial of Service in marked

Quick fix

GHSA-ch52-vgq2-943f — marked: upgrade to the fixed version with the command below.

npm install marked@0.7.0

Details

Affected versions of `marked` are vulnerable to Regular Expression Denial of Service (ReDoS). The `_label` subrule may significantly degrade parsing performance of malformed input.

## Recommendation

Upgrade to version 0.7.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/marked
Introduced in: 0.4.0Fixed in: 0.7.0
Fixnpm install marked@0.7.0

References