⚠️ dependabot-gitlab has detected security vulnerability for @sideway/formula in path: /, manifest_file: /package.json but was unable to update it! ⚠️
dependabot-gitlab
@sideway/formula
/
/package.json
GHSA-c2jc-4fpr-4vhg
CVE-2023-25166
User-provided strings to formula's parser might lead to polynomial execution time.
Users should upgrade to 3.0.1+.
None.
No dependencies set.
The note is not visible to the blocked user.
⚠️
dependabot-gitlabhas detected security vulnerability for@sideway/formulain path:/, manifest_file:/package.jsonbut was unable to update it! ⚠️GHSA-c2jc-4fpr-4vhg,CVE-2023-25166Description
Impact
User-provided strings to formula's parser might lead to polynomial execution time.
Patches
Users should upgrade to 3.0.1+.
Workarounds
None.
References