@milkdown/transformer is vulnerable to Regular Expression Denial of Service (ReDoS)
36
Low Risk
The affected versions use a polynomial-time regular expression within the moveSpaces function, which can lead to performance issues when processing specially crafted input. Specifically, the regular expression exhibits catastrophic backtracking, where certain patterns cause the regex engine to perform excessive computations. An attacker could exploit this by supplying input that triggers worst-case performance, leading to high CPU usage and making the application vulnerable to Regular Expression Denial of Service (ReDoS) attacks. This type of vulnerability can degrade system performance or make the application temporarily unavailable.
You are affected if you are using a version that falls within the vulnerable range.
@milkdown/transformer is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 7.5.5 - 7.13.1.
Upgrade the @milkdown/transformer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant