Intel

AIKIDO-2026-199800

@asamuzakjp/css-color is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-6g4c-jm42-jc5r Published 5 days ago

53

Medium Risk

This Affects:

JS@asamuzakjp/css-color
0.0.1 - 7.0.0
Fixed in 7.0.1
Are you affected? Scan for Free

TL;DR

The resolveColorMix function in src/js/color.ts destructures the result of several RegExp.match() calls without checking whether the match succeeded. A color-mix() value nested three or more levels deep, or otherwise malformed color-mix input, leaves one of these match calls returning null, and destructuring null throws an uncaught TypeError that propagates to the caller. The patch checks each match result and returns the invalid color fallback instead of destructuring null.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@asamuzakjp/css-color is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 7.0.0.

How to fix this

Upgrade the @asamuzakjp/css-color library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform