Vulnerabilities/

Valibot has a ReDoS vulnerability in `EMOJI_REGEX`

Severity:
High

Description

The EMOJI_REGEX used in the emoji action is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. A short, maliciously crafted string (e.g., <100 characters) can cause the regex engine to consume excessive CPU time (minutes), leading to a Denial of Service (DoS) for the application.

Recommendation

Update the valibot package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
valibot
Anything's wrong? Let us know Last updated on November 26, 2025