PT-2025-28037 · Vercel · Vercel Hyper
Dayshift
·
Published
2025-07-05
·
Updated
2025-07-07
·
CVE-2025-7074
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
vercel hyper versions up to 3.4.1
Description:
A problematic vulnerability has been found in vercel hyper, affecting the function
expand/braceExpand/ignoreMap of the file hyper/bin/rimraf-standalone.js. This issue leads to inefficient regular expression complexity and can be initiated remotely. The exploit has been disclosed to the public.Recommendations:
For vercel hyper versions up to 3.4.1, consider updating to a version that fixes the inefficient regular expression complexity issue in the
expand/braceExpand/ignoreMap function.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Resource Exhaustion
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vercel Hyper