Vulnerabilities/

Regular Expression Denial of Service in string package

Severity:
High

Description

Affected versions of string are vulnerable to regular expression denial of service when specifically crafted untrusted user input is passed into the underscore or unescapeHTML methods.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
string
Anything's wrong? Let us know Last updated on September 12, 2023

This issue is available in SmartScanner Professional

See Pricing