VDB
Sign up
HIGH7.5

GHSA-cj88-88mr-972w

glob-parent 6.0.0 vulnerable to Regular Expression Denial of Service

Quick fix

GHSA-cj88-88mr-972w — glob-parent: upgrade to the fixed version with the command below.

npm install glob-parent@6.0.1

Details

glob-parent 6.0.0 is vulnerable to Regular Expression Denial of Service (ReDoS). This issue is fixed in version 6.0.1.

This vulnerability is separate from [GHSA-ww39-953v-wcq6](https://github.com/advisories/GHSA-ww39-953v-wcq6).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/glob-parent
Introduced in: 6.0.0Fixed in: 6.0.1
Fixnpm install glob-parent@6.0.1

References