Intel

AIKIDO-2025-10602

pm2 is vulnerable to Regular Expression Denial of Service (ReDoS)

Regular Expression Denial of Service (ReDoS)CVE-2025-5891 Published Sep 2, 2025

30

Low Risk

This Affects:

JSpm2
0.12.2 - 6.0.8
Fixed in 6.0.9
Are you affected? Scan for Free

TL;DR

Affected versions of this package contain an inefficient regular expression that, when processing specially crafted input, can cause excessive CPU consumption, leading to application hangs or denial of service.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

pm2 is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 0.12.2 - 6.0.8.

How to fix this

Upgrade the pm2 library to the patch version.