Vulnerabilities/

CKEditor 5 Markdown plugin Regular expression Denial of Service

Severity:
Medium

Description

A regular expression denial of service (ReDoS) vulnerability has been discovered in the CKEditor 5 Markdown plugin code. The vulnerability allowed to abuse a link recognition regular expression, which could cause a significant performance drop resulting in a browser tab freeze.

Recommendation

Update the @ckeditor/ckeditor5-markdown-gfm package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@ckeditor/ckeditor5-markdown-gfm
Anything's wrong? Let us know Last updated on January 30, 2023