From d16d62932b0efd1fff79e07075fbab916d0ad4a6 Mon Sep 17 00:00:00 2001 From: sttk Date: Thu, 24 Jun 2021 10:54:06 +0900 Subject: [PATCH] fix: Fix ReDoS vulnerability CVE-2021-35065 --- index.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/index.js b/index.js index f861468..f03304a 100644 --- a/index.js +++ b/index.js @@ -6,7 +6,7 @@ var isWin32 = require('os').platform() === 'win32'; var slash = '/'; var backslash = /\\/g; -var enclosure = /[{[].*\/.*[}\]]$/; +var enclosure = /[{[][^/\r\n\u2028\u2029]*\/.*[}\]]$/; var globby = /(^|[^\\])([{[]|\([^)]+$)/; var escaped = /\\([!*?|[\](){}])/g;