VDB
Sign up
HIGH7.5

GHSA-p28h-cc7q-c4fg

css-what vulnerable to ReDoS due to use of insecure regular expression

Quick fix

GHSA-p28h-cc7q-c4fg — css-what: upgrade to the fixed version with the command below.

npm install css-what@2.1.3

Details

The package css-what before 2.1.3 is vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of insecure regular expression in the `re_attr` variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/css-what
Introduced in: 0Fixed in: 2.1.3
Fixnpm install css-what@2.1.3

References