—
PYSEC-2024-48
Quick fix
PYSEC-2024-48 — black: upgrade to the fixed version with the command below.
pip install --upgrade 'black>=f00093672628d212b8965a8993cee8bedf5fe9b8'Details
Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file. An attacker could exploit this vulnerability by crafting a malicious input that causes a denial of service. Exploiting this vulnerability is possible when running Black on untrusted input, or if you habitually put thousands of leading tab characters in your docstrings.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/black
Introduced in:
0Fixed in: f00093672628d212b8965a8993cee8bedf5fe9b8Fix
pip install --upgrade 'black>=f00093672628d212b8965a8993cee8bedf5fe9b8'