sasstools/scss-tokenizer

sasstools/scss-tokenizer

Releases13
Frequency7 months 6 days
Last Release
Stars25
A tokenzier for Sass' SCSS syntax

CVE History

CVEPublishedCVSS v3CVSS v2
5.3 MEDIUM5 MEDIUM

All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.