High severity7.0NVD Advisory· Published Jun 30, 2025· Updated Jun 17, 2026
CVE-2025-45143
CVE-2025-45143
Description
string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
string-mathnpm | <= 1.2.2 | — |
Affected products
3- string-math/string-mathdescription
- cpe:2.3:a:devrafalko:string-math:1.2.2:*:*:*:*:node.js:*:*
Patches
Vulnerability mechanics
References
5- gist.github.com/6en6ar/361608bccedb808061359481fe2f1b39nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-994j-5c83-r424ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-45143ghsaADVISORY
- github.com/devrafalko/string-math/blob/master/string-math.jsnvdProductWEB
- www.npmjs.com/package/string-math%2CnvdBroken LinkWEB
News mentions
0No linked articles in our index yet.