All versions of package dat.gui are vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted rgb and rgba values.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-JS-DATGUI-1016275 | third party advisory |
https://github.com/dataarts/dat.gui/issues/278 | third party advisory exploit |