Executive brief
string-math is a JavaScript library that parses and evaluates mathematical expressions stored as strings. A regular expression in the library's parsing logic is vulnerable to denial-of-service attacks when processing specially crafted inputs, which can cause the application to hang or crash.
Technical details
The vulnerability is a Regex Denial of Service (ReDoS) in the regular expression at line 7 of string-math.js (CWE-1333). The vulnerable regex exhibits catastrophic backtracking when processing long inputs containing tabs and null bytes followed by function-call-like patterns, causing exponential processing time. An unauthenticated attacker with network access can exploit this by sending a crafted payload (e.g., repeated tabs and padded expressions) to any application using the library. This causes the application to become unresponsive. No patch is currently mentioned in the available advisory information.
Affected products
- string-math string-math up to 1.2.2
Timeline
- 2025-06-30: disclosed