Vulnerabilities/

Terser insecure use of regular expressions leads to ReDoS

Severity:
High

Description

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.

Recommendation

Update the terser package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
terser
Anything's wrong? Let us know Last updated on April 11, 2023

This issue is available in SmartScanner Professional

See Pricing