Vulnerabilities/

Uncontrolled Resource Consumption in ansi-html

Severity:
High

Description

This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.

Recommendation

Update the ansi-html package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ansi-html
Anything's wrong? Let us know Last updated on February 12, 2025