sass / node-sass-middleware

connect middleware extracted from node-sass
MIT License
263 stars 84 forks source link

Regular expression denial of service in scss-tokenizer #158

Open WardBrink opened 2 years ago

WardBrink commented 2 years ago

Hi,

There is a vulnerability in this package, which can be updated if the dependency scss-tokenizer is at least version 0.4.3.

See also: https://github.com/advisories/GHSA-7mwh-4pqv-wmr8

Could you patch this?

YasharF commented 1 year ago

This seems to be fixed already.