Prism is a syntax highlighting library. The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted HTML comment as input may cause an application to consume an excessive amount of CPU.
{ "github_reviewed": true, "cwe_ids": [ "CWE-400" ], "severity": "MODERATE", "github_reviewed_at": "2021-09-16T18:29:46Z", "nvd_published_at": "2021-09-15T13:15:00Z" }