CVE-2025-8263 Information

Description

A vulnerability was found in prettier up to 3.6.2. It has been declared as problematic. Affected by this vulnerability is the function parseNestedCSS of the file src/language-css/parser-postcss.js. The manipulation of the argument node leads to inefficient regular expression complexity. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Reference

https://github.com/prettier/prettier/issues/17737 https://github.com/prettier/prettier/issues/17737#issue-3238184068 https://vuldb.com/?ctiid.317851 https://vuldb.com/?id.317851 https://vuldb.com/?submit.617593

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

LOW

Base Severity

4.3

CNNVD-202507-3474 (Published: 2025-07-28)

Share on: