VDB
Sign up
HIGH7.4

GHSA-gj77-59wh-66hg

Regular Expression Denial of Service (ReDoS) in Prism

Quick fix

GHSA-gj77-59wh-66hg — prismjs: upgrade to the fixed version with the command below.

npm install prismjs@1.24.0

Details

Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS).

### Impact

When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. Do not use the following languages to highlight untrusted text.

- ASCIIDoc - ERB

Other languages are __not__ affected and can be used to highlight untrusted text.

### Patches This problem has been fixed in Prism v1.24.

### References

- PrismJS/prism#2774 - PrismJS/prism#2688

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/prismjs
Introduced in: 0Fixed in: 1.24.0
Fixnpm install prismjs@1.24.0

References