VDB
Sign up
LOW

GHSA-cwfw-4gq5-mrqx

Regular Expression Denial of Service (ReDoS) in braces

Quick fix

GHSA-cwfw-4gq5-mrqx — braces: upgrade to the fixed version with the command below.

npm install braces@2.3.1

Details

A vulnerability was found in Braces versions from v2.2.0 up to but not including v2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks. This has been patched in version 2.3.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/braces
Introduced in: 2.2.0Fixed in: 2.3.1
Fixnpm install braces@2.3.1

References