Impact
The brace‑expansion library processes strings with brace syntax to generate many combinations. Prior to specific releases, a pattern with deeply nested braces causes the library to recurse once for each level of nesting when expanding comma‑separated members or single set members. The uncontrolled recursion exhausts the native stack before any output limits are reached, terminating the Node.js process and resulting in a denial of service. This flaw is directly tied to resource exhaustion (CWE‑400) and improper recursion control (CWE‑674). The impact is primarily availability, as a rogue input can force the application to crash or become unresponsive. The CVSS score of 7.5 indicates a medium‑to‑high severity vulnerability.
Affected Systems
The vulnerability affects the brace‑expansion package maintained by juliangruber. Versions prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11 are vulnerable. Any Node.js application that imports this library and accepts untrusted input containing brace syntax, such as command‑line utilities, build tools, or web services, may be exposed.
Risk and Exploitability
An attacker can supply a crafted pattern with many nested braces to the library. Because the library performs uncontrolled recursion, the attack requires only a legitimate call to the expand function with malicious input; no special privileges or credentials are needed. The lack of an EPSS score and absence from the KEV catalog suggest that this vulnerability has not yet been widely exploited, but the medium‑high CVSS rating and the straightforward attack vector elevate the risk for deployments that rely on user‑provided brace expressions.
OpenCVE Enrichment