VDB
Sign up
HIGH7.5

GHSA-r8j5-h5cx-65gg

ReDOS in IS-SVG

Quick fix

GHSA-r8j5-h5cx-65gg — is-svg: upgrade to the fixed version with the command below.

npm install is-svg@4.3.0

Details

A vulnerability was discovered in IS-SVG version 4.3.1 and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and checks a crafted invalid SVG string.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/is-svg
Introduced in: 2.1.0Fixed in: 4.3.0
Fixnpm install is-svg@4.3.0

References