mjmlio / mjml

MJML: the only framework that makes responsive-email easy
https://mjml.io
MIT License
17.1k stars 961 forks source link

High Severity Vulnerability in html-minifier #2589

Open PavelBurya opened 1 year ago

PavelBurya commented 1 year ago

Hello, our security check has found a high severity vulnerability in html-minifier, which is a dependency of mjml.

Dependency hierarchy:

Vulnerability description: A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 via the candidate variable in htmlminifier.js.

Here is a link to a similar issue in html-minifier. It does not seem to be worked on.

https://github.com/kangax/html-minifier/issues/1135

Can you update your repository to get rid of this vulnerability?