Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-9670

Опубликовано: 29 авг. 2025
Источник: debian

Описание

A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src/commonmark-rules.js. Performing manipulation results in inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-turndownfixed7.2.2+~2.2.0~git20240406-1package
node-turndownno-dsatrixiepackage
node-turndownno-dsabookwormpackage

Примечания

  • https://github.com/mixmark-io/turndown/issues/501

  • https://github.com/mixmark-io/turndown/pull/504

  • https://github.com/mixmark-io/turndown/commit/8ed049935ac235cc009e9a7412c0a6fe6ab5b223 (v7.2.2)

Связанные уязвимости

CVSS3: 5.3
ubuntu
5 месяцев назад

A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src/commonmark-rules.js. Performing manipulation results in inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.

CVSS3: 5.3
nvd
5 месяцев назад

A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src/commonmark-rules.js. Performing manipulation results in inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.

CVSS3: 5.3
github
5 месяцев назад

A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src/commonmark-rules.js. Performing manipulation results in inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.