Vulnerabilities/

Inefficient Regular Expression Complexity in chalk/ansi-regex

Severity:
High

Description

ansi-regex is vulnerable to Inefficient Regular Expression Complexity which could lead to a denial of service when parsing invalid ANSI escape codes.

Proof of Concept

The ReDOS is mainly due to the sub-patterns [[\\]()#;?]* and (?:;[-a-zA-Z\\d\\/#&.:=?%@~_]*){:target="_blank"}{:rel="noopener noreferrer"}*

Recommendation

Update the ansi-regex package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ansi-regex
Anything's wrong? Let us know Last updated on September 21, 2023