CVE-2025-25285

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 14, 2025
CWE ID 1333

Summary

CVE-2025-25285 is a vulnerability affecting the `@octokit/endpoint` npm package, specifically versions 4.1.0 to 10.1.2. The issue lies within the `parse` function in the `parse.ts` file, which can be triggered by crafted `options` parameters. This results in a regular expression denial-of-service (ReDoS) attack, causing the program to hang and consume high CPU resources. By exploiting this vulnerability, an attacker can induce the application to become unresponsive and consume significant computational power. The vulnerability has been addressed in version 10.1.3 of the package.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share