tarojs taro index.js redos

CVE Details

Basic Information

Title tarojs taro index.js redos
Type cve
Published 2025-06-09T20:31:07.141Z
Last Seen

Product Information

Vendor tarojs
Product taro
Version 4.1.0

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A regular expression complexity vulnerability in tarojs taro versions up to 4.1.1 could allow remote attackers to cause inefficient processing via a ReDoS attack. Upgrade to version 4.1.2 to fix this issue.
AI Severity Medium
Vendor TaroJS Community
Product tarojs taro
Affected Version 4.1.0, 4.1.1

Affected Products

  • tarojs taro 4.1.0
  • tarojs taro 4.1.1

Additional Information

CVE List
CWE List CWE-1333, CWE-400
Bulletin Family

Description

A vulnerability was found in tarojs taro up to 4.1.1. It has been declared as problematic. This vulnerability affects unknown code of the file taro/packages/css-to-react-native/src/index.js. The manipulation leads to inefficient regular expression complexity. The attack can be initiated remotely. Upgrading to version 4.1.2 is able to address this issue. The name of the patch is c2e321a8b6fc873427c466c69f41ed0b5e8814bf. It is recommended to upgrade the affected component.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.