GHSA-5j4c-8p2g-v4jx

    Dashboard / Vulnerabilities / GHSA-5j4c-8p2g-v4jx

    GHSA-5j4c-8p2g-v4jx

    Published: 15 Oct 2024Last Modified: 10 Sept 2026
    Aliases:

    Summary: ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function

    Details: The ReDoS can be exploited through the `parseHTML` function in the `html-parser.ts` file. This flaw allows attackers to slow down the application by providing specially crafted input that causes inefficient processing of regular expressions, leading to excessive resource consumption. To demonstrate this vulnerability, here's an example. In a Vue client-side application, create a new Vue instance with a template string that includes a `<script>` tag but closes it incorrectly with something like `</textarea>`. ```javascript new Vue({ el: '#app', template: ' <div> Hello, world! <script>${'<'.repeat(1000000)}</textarea> </div>' }); ``` Next, set up a basic HTML page (e.g., index.html) to load this JavaScript and mount the Vue instance: ```html <!DOCTYPE html> <html> <head> <title>My first Vue app</title> </head> <body> <div id=\"app\">Loading...</div> </body> </html> ``` When you visit the app in your browser at http://localhost:3000, you'll notice that the time taken to parse and mount the Vue application increases significantly due to the ReDoS vulnerability, demonstrating how the flaw can affect performance.

    Affected packages

    Package

    Name: vue

    Purl: pkg:npm/vue

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 2.0.0-alpha.1
    Fixed -3.0.0-alpha.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-5j4c-8p2g-v4jx | CVE-DB