Vulnerabilities/

string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)

Severity:
Low

Description

string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
string-math
Anything's wrong? Let us know Last updated on June 30, 2025