Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug] html-minifier high severity vulnerability #268

Closed
Tpleme opened this issue Jul 17, 2024 · 4 comments
Closed

[Bug] html-minifier high severity vulnerability #268

Tpleme opened this issue Jul 17, 2024 · 4 comments
Labels
bug Something isn't working

Comments

@Tpleme
Copy link

Tpleme commented Jul 17, 2024

Describe the bug
A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0.
html-minifier

Additional context
A ReDos was found on this package, and it seems that they won't patch it, their last update was 5 years ago.
MJML lauched a alpha version replacing it with htmlnano and prettier (issue here).

@Tpleme Tpleme added the bug Something isn't working label Jul 17, 2024
@Thomascogez
Copy link
Owner

Thanks for the report !
I check the [email protected] branch has you recommended until the official release of mjml@5 version

Thanks again for you interest ! I will take a look at this in the few day and release a new minor version of this package 👍

@Tpleme
Copy link
Author

Tpleme commented Jul 18, 2024

Hi, thanks for that, i really appreciate your effort on maintaining this package, this has been very useful for me :D
I could adventure myself on making a PR but i think this is not something i can handle.

@Thomascogez
Copy link
Owner

Hey @Tpleme, Thanks for your feedback ! And i'm glad that this package has been useful for you ! I just release 1.4.0 with the changes that has been discussed before 👍. You can check the full upgrade/migration guide right here https://github.com/Thomascogez/nodemailer-mjml/blob/master/MIGRATION_GUIDES/FROM_1.3.X_TO_1.4.md

@Tpleme
Copy link
Author

Tpleme commented Jul 20, 2024

Thank you very much. Really appreciate your time. Gonna close this. :P

@Tpleme Tpleme closed this as completed Jul 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants