QID 982877
QID 982877: Nodejs (npm) Security Update for @progfay/scrapbox-parser (GHSA-9fhw-r42p-5c7r)
Security update has been released for @progfay/scrapbox-parser to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A [Regular expression Denial of Service](https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS) flaw was found in the @progfay/scrapbox-parser package before 6.0.3, 7.0.2 for Node.js.
The attacker that is able to be parsed a specially crafted text may cause the application to consume an excessive amount of CPU.
Solution
Upgrade to version 6.0.3, 7.0.2 or later.Workaround:
Avoid to parse text with a lot of `[` chars.
Avoid to parse text with a lot of `[` chars.
Vendor References
- GHSA-9fhw-r42p-5c7r -
github.com/advisories/GHSA-9fhw-r42p-5c7r
CVEs related to QID 982877
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9fhw-r42p-5c7r | @progfay/scrapbox-parser |
|