stealjs / steal

Gets JavaScript
https://stealjs.com
MIT License
1.37k stars 521 forks source link

[CVE-2022-37263]/ReDos found in babel.js #1532

Open secdevlpr26 opened 1 year ago

secdevlpr26 commented 1 year ago

A Regular expression denial of service (ReDoS) flaw was found in Function win32 in babel.js in stealjs steal 2.2.4 via the path variable in babel.js.

The ReDoS vulnerability can be mitigated with several best practices described here: https://snyk.io/blog/redos-and-catastrophic-backtracking/