VDB
Sign up
MEDIUM6.5

GHSA-hqhp-5p83-hx96

prismjs Regular Expression Denial of Service vulnerability

Quick fix

GHSA-hqhp-5p83-hx96 — prismjs: upgrade to the fixed version with the command below.

npm install prismjs@1.25.0

Details

Prism is a syntax highlighting library. The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted HTML comment as input may cause an application to consume an excessive amount of CPU.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/prismjs
Introduced in: 0Fixed in: 1.25.0
Fixnpm install prismjs@1.25.0

References