PT-2025-22799 · Marked · Marked

Published

2025-05-23

·

Updated

2025-05-26

·

CVE-2018-25110

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Marked versions prior to 0.3.17
Description The issue is related to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this by providing specially crafted markdown input, such as deeply nested or repetitively structured brackets or tag attributes, which cause the parser to hang and lead to a Denial of Service.
Recommendations For versions prior to 0.3.17, update to version 0.3.17 or later to resolve the issue. As a temporary workaround, consider restricting the use of markdown input to prevent exploitation until a patch is applied. Avoid using deeply nested or repetitively structured brackets or tag attributes in markdown links to minimize the risk of exploitation.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-25110
GHSA-P9WX-2529-FP83

Affected Products

Marked