CVE-2025-5890 PUBLISHED

actions toolkit glob internal-pattern.ts globEscape redos

Assigner: VulDB
Reserved: 09.06.2025 Published: 09.06.2025 Updated: 09.06.2025

A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 5.3

Product Status

Vendor actions
Product toolkit
Versions
  • Version 0.5.0 is affected

Credits

  • mmmsssttt (VulDB User) reporter

References

Problem Types

  • Inefficient Regular Expression Complexity CWE
  • Resource Consumption CWE