VDB
Sign up
MEDIUM5.0

GHSA-prr3-c3m5-p7q2

@adobe/css-tools Improper Input Validation and Inefficient Regular Expression Complexity

Quick fix

GHSA-prr3-c3m5-p7q2 — @adobe/css-tools: upgrade to the fixed version with the command below.

npm install @adobe/css-tools@4.3.2

Details

### Impact @adobe/css-tools version 4.3.1 and earlier are affected by an Improper Input Validation vulnerability that could result in a denial of service while attempting to parse CSS.

### Patches The issue has been resolved in 4.3.2.

### Workarounds None

### References N/A

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@adobe/css-tools
Introduced in: 0Fixed in: 4.3.2
Fixnpm install @adobe/css-tools@4.3.2

References