Versions of vue-moment prior to 4.1.0 contain an Outdated Static Dependency. The package depends on moment and has it loaded statically instead of as a dependency that can be updated. It has moment@2.19.1 that contains a Regular Expression Denial of Service vulnerability.
Upgrade to version 4.1.0 or later.
{
"cwe_ids": [
"CWE-1104"
],
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T18:58:51Z",
"nvd_published_at": null,
"severity": "MODERATE"
}