danocmx/node-tf2-item-format

danocmx/node-tf2-item-format

Releases94
Frequency2 weeks 5 days
Last Release
Stars25
Fully typed battle-tested library that helps you format TF2 items to the community standards.

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4.2.6` and prior to `5.9.14` are vulnerable to a Regular Expression Denial of Service (ReDoS) attack when parsing crafted user input. This vulnerability can be exploited by an attacker to perform DoS attacks on any service that uses any `tf2-item-format` to parse user input. Version `5.9.14` contains a fix for the issue.