Vulnerabilities/

@isaacs/brace-expansion has Uncontrolled Resource Consumption

Severity:
High

Description

@isaacs/brace-expansion is vulnerable to a Denial of Service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously.

Recommendation

Update the @isaacs/brace-expansion package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@isaacs/brace-expansion
Anything's wrong? Let us know Last updated on February 05, 2026