HIGH7.5
GHSA-r8j5-h5cx-65gg
ReDOS in IS-SVG
Quick fix
GHSA-r8j5-h5cx-65gg — is-svg: upgrade to the fixed version with the command below.
npm install is-svg@4.3.0Details
A vulnerability was discovered in IS-SVG version 4.3.1 and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and checks a crafted invalid SVG string.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-29059[ADVISORY]
- https://github.com/sindresorhus/is-svg/commit/732fc72779840c45a30817d3fe28e12058592b02[WEB]
- https://github.com/sindresorhus/is-svg[PACKAGE]
- https://github.com/sindresorhus/is-svg/releases/tag/v4.3.0[WEB]
- https://github.com/yetingli/PoCs/blob/main/CVE-2021-29059/IS-SVG.md[WEB]
- https://github.com/yetingli/SaveResults/blob/main/js/is-svg.js[WEB]
- https://www.npmjs.com/package/is-svg[WEB]