@quasar/app-vite is vulnerable to Regular Expression Denial of Service (ReDoS)
75
High Risk
A regular expression Denial of Service (ReDoS) vulnerability was found in kangax html-minifier 4.0.0 through the candidate variable in htmlminifier.js. Since this issue does not receive a fix, the package switches to a different implementation for the HTML minifier.
You are affected if you are using a version that falls within the vulnerable range.
@quasar/app-vite is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 1.0.0 - 1.8.2.
Upgrade the @quasar/app-vite library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant