-
-
Notifications
You must be signed in to change notification settings - Fork 102
Open
Description
Hi 👋,
I would like to report a security vulnerability affecting your project through a transitive dependency, one of which is now deprecated.
📌 Vulnerability Details
- Affected package:
valibot - Vulnerable versions:
>=0.31.0 <1.2.0 - Severity: High
- Type: ReDoS (Regular Expression Denial of Service)
- Cause: Vulnerable
EMOJI_REGEX - Official advisory: GHSA-vqpr-j7v3-hqw9
📦 Dependency chain involved
sveltekit-superforms → @gcornut/valibot-json-schema (deprecated) → valibot
⚠️ Impact
An attacker can exploit the vulnerable regex to trigger a Denial of Service (ReDoS) via specially crafted input.
🛠 Recommendation
- Update
valibotto ≥ 1.2.0 or any version containing the fix. - Since
@gcornut/valibot-json-schemais deprecated, consider replacing it with a maintained alternative or a suitable JSON Schema mapping solution.
(The official repo indicates the deprecation: https://github.com/gcornut/valibot-json-schema)
🙏 Thanks
Thank you for your work on this project..
oasis-jesse, patte, 0LL1, itay-grudev, armaneous and 3 more
Metadata
Metadata
Assignees
Labels
No labels