Executive brief
marked is a popular JavaScript markdown parser library used in web applications and build tools. A flaw in versions 0.5.0 through 0.6.0 allows attackers to trigger a denial-of-service condition by crafting malicious markdown input with parentheses in link URIs combined with multiple link tokens on a single line, causing the parser to enter excessive regex backtracking and consume server resources until the application becomes unresponsive.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) flaw in the hostname regex pattern used by marked's link parsing logic. The vulnerable component processes the "host" variable when parsing link URIs and fails to properly handle nested parentheses, causing catastrophic regex backtracking. An attacker can exploit this by submitting markdown with specially crafted link syntax containing multiple parentheses and link tokens on a single line. No authentication is required; the attack vector is network-based through any application that accepts and processes untrusted markdown input. The issue was fixed in version 0.6.1 by restricting nested parentheses to a single level in link URIs.
Affected products
- marked.js marked 0.5.0 to 0.6.0
Timeline
- 2019-02-21: disclosed
- 2019-01-13: patched: Fix committed upstream; released in version 0.6.1
- 2021-02-25: advisory: GHSA-7m7q-q53v-j47v published