Junglewise Threat Intelligence

Stylelint transitive semver regular expression denial of service

Severity: info · Published 2023-07-07

Vendors: npm.

Executive brief

Stylelint, a popular CSS linting tool, depended on a version of the semver library that contains a regular expression denial of service (ReDoS) vulnerability. An attacker could trigger excessive CPU consumption by providing specially crafted input to the CLI. Impact is limited since Stylelint is typically used only during development and as a build-time tool, not in production systems.

Technical details

The vulnerability exists in semver version 5.7.1, which was a transitive dependency pulled in through the meow CLI framework (via read-pkg and normalize-package-data). The semver library contains a ReDoS flaw in its regular expression parsing logic (tracked separately as CVE-2022-25883 / GHSA-c2qf-rxjj-qqgw). Stylelint 8.0.0 through 15.10.0 are affected. The attack vector requires network access or local CLI invocation with untrusted input to the semver parser. The fix is available in Stylelint 15.10.1 and later, which updates dependencies to use patched versions of semver (7.5.2+, 6.x, or 5.x backport versions).

Affected products

  • Stylelint Stylelint 8.0.0 to 15.10.0

Timeline

  • 2023-07-07: disclosed
  • 2023-07-07: patched: Stylelint 15.10.1 released with patched dependencies
  • 2023-07-13: other: Advisory withdrawn; noted that direct semver update in user projects can also resolve the issue

References