Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17579 | A vulnerability was found in vuejs vue-cli up to 5.0.8. It has been rated as problematic. This issue affects the function HtmlPwaPlugin of the file packages/@vue/cli-plugin-pwa/lib/HtmlPwaPlugin.js of the component Markdown Code Handler. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely. |
Github GHSA |
GHSA-79vf-hf9f-j9q8 | @vue/cli-plugin-pwa Regular Expression Denial of Service vulnerability |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 10 Jul 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vuejs
Vuejs vue Cli |
|
| CPEs | cpe:2.3:a:vuejs:vue_cli:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vuejs
Vuejs vue Cli |
Tue, 10 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in vuejs vue-cli up to 5.0.8. It has been rated as problematic. This issue affects the function HtmlPwaPlugin of the file packages/@vue/cli-plugin-pwa/lib/HtmlPwaPlugin.js of the component Markdown Code Handler. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely. | |
| Title | vuejs vue-cli Markdown Code HtmlPwaPlugin.js HtmlPwaPlugin redos | |
| Weaknesses | CWE-1333 CWE-400 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-06-10T15:29:58.751Z
Reserved: 2025-06-09T07:02:15.578Z
Link: CVE-2025-5897
Updated: 2025-06-10T14:22:19.901Z
Status : Analyzed
Published: 2025-06-09T21:15:47.707
Modified: 2025-07-10T16:28:50.510
Link: CVE-2025-5897
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA