PT-2025-36518 · Cattown · Cattown

·

CVE-2025-58451

·

Published

2025-09-08

·

Updated

2025-09-09

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Cattown versions prior to 1.0.2
Description: Cattown is a JavaScript markdown parser susceptible to denial of service. The parser utilizes regular expressions with inefficient complexity, potentially leading to exponential worst-case backtracking. Processing crafted inputs can cause excessive CPU usage, potentially leading to resource exhaustion.
Recommendations: Update to version 1.0.2 or later. Review and restrict input sources if untrusted inputs are processed.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-58451
GHSA-455V-W7R9-3VV9

Affected Products

Cattown