Skip to main content

Inefficient Regular Expression Complexity

CVE-2025-5897

Severity Medium
Score 5.3/10

Summary

A vulnerability was found in VueJS Vue-CLI. It has been rated as problematic. This issue affects the function "HtmlPwaPlugin" of the file "packages/@vue/cli-plugin-pwa/lib/HtmlPwaPlugin.js" of the component Markdown Code Handler. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-1333 - Inefficient Regular Expression Complexity

The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Advisory Timeline

  • Published