Junglewise Threat Intelligence

CVE-2025-5891: Unitech pm2 ReDoS in Config.js

CVE-2025-5891 · Severity: medium · CVSS 4.3 · Published 2025-06-09

Vendors: npm.

Executive brief

A vulnerability was found in pm2, a popular process manager for Node.js applications. An attacker can exploit a flaw in how the software handles configuration data to cause a denial-of-service condition. This could lead to high CPU usage and make the application management service unresponsive, potentially impacting the availability of hosted services.

Technical details

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Unitech pm2 prior to version 7.0.0. The flaw is located in the `/lib/tools/Config.js` file, where inefficient regular expression complexity allows for uncontrolled resource consumption. A remote attacker with low privileges can provide specially crafted input that triggers catastrophic backtracking during regex evaluation. This results in excessive CPU consumption, leading to a denial-of-service (DoS) state for the pm2 process. The issue is addressed in version 7.0.0.

Affected products

  • Unitech pm2 < 7.0.0

Timeline

  • 2025-06-09: disclosed
  • 2025-06-09: advisory
  • 2025-06-09: patched: Fixed in version 7.0.0

References