Sisimai · Sisimai · CVE-2022-4891
**Name of the Vulnerable Software and Affected Versions**
Sisimai versions up to 4.25.14p11
**Description**
A vulnerability has been found in the function `to plain` of the file `lib/sisimai/string.rb`, leading to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used.
**Recommendations**
For Sisimai versions up to 4.25.14p11, upgrade to version 4.25.14p12 to address this issue. As a temporary workaround, consider restricting the use of the `to plain` function in the `lib/sisimai/string.rb` file until the patch is applied.