Impact
The vulnerability is an input validation flaw in source-map-js that allows an attacker to supply arbitrary numeric values for the per-section offset line in indexed source maps. These oversized values cause the library to execute synchronously for extended periods, blocking the event loop and preventing the application from handling other requests. The weakness is classified as CWE-1284 and CWE-1285, both involving improper validation of numeric input.
Affected Systems
Affected vendor "7rulnik" and its product "source-map-js". Versions through and including 1.2.1 are impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity impact, and the EPSS score of less than 1% suggests the likelihood of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to involve an attacker who can supply a crafted source map file that is processed by the library, such as through a malicious dependency upload or an untrusted source map used in an application. The denial of service manifests as a prolonged synchronous event loop block, which may affect multiple concurrent users while the processing occurs.
OpenCVE Enrichment
Github GHSA