A denial-of-service (infinite loop) can occur in text() / textSync() when
both:
whitespaceBreak: true is set, andwidth is set smaller than the rendered width of a single FIGlet character.
Under these conditions breakWord() could never find a valid break point, so the
word-wrapping loop in generateFigTextLines() never terminated. This pins a CPU
core and grows memory without bound, blocking the Node.js event loop.Low or Medium. Triggering requires a non-default configuration (whitespaceBreak: true) and
an attacker-controlled width value reaching text()/textSync(). This library is typically
used with fixed options, where this is not
reachable. Applications that pass an untrusted width together with
whitespaceBreak on a request path are affected.
Fixed in figlet 1.11.3. breakWord() now always makes forward progress
(emitting an over-wide character on its own line), and FIGlet header parsing now
rejects invalid values (e.g. zero/negative height).
Do not expose width to untrusted input, or leave whitespaceBreak disabled
(the default), or upgrade to 1.11.3.
{
"cwe_ids": [
"CWE-835"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-02T22:39:16Z",
"nvd_published_at": "2026-10-01T21:17:26Z",
"severity": "HIGH"
}