VDB
Sign up
HIGH7.5

GHSA-x5pg-88wf-qq4p

Regular Expression Denial of Service in marked

Quick fix

GHSA-x5pg-88wf-qq4p — marked: upgrade to the fixed version with the command below.

npm install marked@0.3.9

Details

Affected versions of `marked` are vulnerable to a regular expression denial of service.

The amplification in this vulnerability is significant, with 1,000 characters resulting in the event loop being blocked for around 6 seconds.

## Recommendation

Update to version 0.3.9 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/marked
Introduced in: 0Fixed in: 0.3.9
Fixnpm install marked@0.3.9

References