@unocss/extractor-arbitrary-variants is vulnerable to Regular Expression Denial of Service (ReDoS)
50
Medium Risk
The affected versions use a regular expression with inefficient, possibly exponential worst-case computational complexity, leading to excessive CPU consumption. This issue occurs at lines 5–7 in packages/extractor-arbitrary-variants/src/index.ts.
You are affected if you are using a version that falls within the vulnerable range.
@unocss/extractor-arbitrary-variants is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 0.51.0 - 0.58.3.
Upgrade the @unocss/extractor-arbitrary-variants library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant