A vulnerability classified as problematic has been found...
Moderate severity
Unreviewed
Published
Jun 9, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jun 9, 2025
Published to the GitHub Advisory Database
Jun 9, 2025
A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely.
References