MEDIUM6.5
GHSA-hqhp-5p83-hx96
prismjs Regular Expression Denial of Service vulnerability
Quick fix
GHSA-hqhp-5p83-hx96 — prismjs: upgrade to the fixed version with the command below.
npm install prismjs@1.25.0Details
Prism is a syntax highlighting library. The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted HTML comment as input may cause an application to consume an excessive amount of CPU.
Are you affected?
Enter the version of the package you're using.