Impact
The braces library (v3.0.3) contains a stack overflow caused by recursive abstract syntax tree walkers that lack depth guarding. An attacker can craft deeply nested brace patterns within the allowed character limit. When the parser processes these patterns, the unbounded recursion exhausts the Node.js call stack and throws an uncaught RangeError, terminating the Node.js process and resulting in a denial‑of‑service condition.
Affected Systems
Any Node.js application that imports or depends on micromatch braces version 3.0.3 is affected, as the library's recursive walkers are used during pattern compilation.
Risk and Exploitability
The CVSS score of 8.7 reflects high severity, while the EPSS score of < 1% indicates a very low but nonzero probability of exploitation. The vulnerability is not listed in CISA KEV. Attackers only need to supply a malicious pattern to trigger the stack overflow; the vector is likely local or remote through user-supplied input to the braces parser, and the exploitation does not require elevated privileges.
OpenCVE Enrichment
Github GHSA