Impact
basic-ftp uses a regular expression (RE_LINE) to parse Unix directory listings. An attacker can craft a line that satisfies an initial part of the pattern but not the later size and date elements, causing the expression to backtrack extensively and consume quadratic CPU time. The effect is a denial of service in the Node.js event loop, as the parsing process stalls the client application. This flaw aligns with CWE-1333 (Regular Expression Denial of Service). The attack vector is inferred to be a malicious or compromised FTP server that sends the specially crafted listing when Client.list() is invoked; a local attacker does not require elevated privileges for exploitation.
Affected Systems
All releases of patrickjuchli basic-ftp before version 6.2.1 are affected, regardless of Node.js runtime version. This includes any environment that imports the basic-ftp package and calls Client.list() against a remote FTP server.
Risk and Exploitability
With a CVSS score of 8.2, the vulnerability is considered high risk. EPSS data is not available, so the current exploitation probability cannot be quantified, but the flaw is straightforward to trigger from a remote FTP server and is not listed in the CISA KEV catalog. An attacker only needs to supply a crafted directory listing after establishing an FTP connection; no local privileges or additional exploits are required. The event loop freeze means the entire Node.js process may become unresponsive until the client terminates or restarts.
OpenCVE Enrichment