Executive brief
simple-markdown is a JavaScript markdown parser used to convert markdown-like text into structured content. Versions before 0.5.2 are vulnerable to a regular expression denial of service (ReDoS) attack through specially crafted inline code blocks with many spaces. An attacker can send such content to cause the parser to consume excessive CPU resources and slow down or temporarily unavail applications that use the library. The vulnerability is fixed in version 0.5.2 and later.
Technical details
The vulnerability is a regular expression denial of service (ReDoS) in the inline code parsing regex used by the SimpleMarkdown.defaultInlineParse() function. The vulnerable regex pattern contained overlapping alternatives—specifically, spaces could be matched by either the `\s*` quantifiers or the `[\S\s]*` capture group—leading to catastrophic backtracking when processing strings with many consecutive spaces. The attack requires no authentication and is exploitable remotely via any code path that parses user-supplied markdown input. An attacker can cause severe performance degradation or temporary denial of service. The fix, deployed in commit 89797fe and released in version 0.5.2, removes the problematic `\s*` parts from the regex and instead handles escaping logic post-parsing.
Affected products
- Khan Academy simple-markdown <0.5.2
Timeline
- 2019-08-30: disclosed
- 2020-09-03: advisory
- 2019: patched: Fix committed in version 0.5.2