Vulnerabilities/

prismjs Regular Expression Denial of Service vulnerability

Severity:
Medium

Description

Prism is a syntax highlighting library. The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted HTML comment as input may cause an application to consume an excessive amount of CPU.

Recommendation

Update the prismjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
prismjs
Anything's wrong? Let us know Last updated on January 29, 2023

This issue is available in SmartScanner Professional

See Pricing