Junglewise Threat Intelligence

CVE-2025-5897: Vue CLI PWA plugin regular expression denial of service

CVE-2025-5897 · Severity: low · CVSS 3.1 · Published 2025-06-09

Vendors: npm.

Executive brief

Vue CLI's PWA plugin contains an inefficient regular expression that can be exploited to cause a denial of service. An attacker with network access can send specially crafted input to the Markdown code handler in the HtmlPwaPlugin component, causing the build process or related tooling to hang or consume excessive CPU resources, disrupting development workflows.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) in the HtmlPwaPlugin component of @vue/cli-plugin-pwa, specifically in the Markdown code handler function. The affected code uses an inefficient regular expression with excessive backtracking (CWE-1333, CWE-400), allowing remote attackers to supply malicious input that causes polynomial-time regex evaluation. No authentication or user interaction is required; the attack can be initiated remotely over the network. An attacker can cause denial of service by exhausting CPU resources during build time. A fix has been proposed in GitHub pull request #7478.

Affected products

  • Vue.js cli-plugin-pwa up to 5.0.8

Timeline

  • 2025-06-09: disclosed: Vulnerability published to GitHub Advisory Database
  • 2025-05-07: other: Patch proposed via GitHub pull request #7478

References