CVE-2025-7074: vercel hyper rimraf-standalone.js ignoreMap redos
A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the file hyper/bin/rimraf-standalone.js. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7074?
CVE-2025-7074 is classified as a problematic vulnerability.
How do I fix CVE-2025-7074?
To fix CVE-2025-7074, upgrade Vercel Hyper to version 3.4.2 or later.
What component is affected by CVE-2025-7074?
CVE-2025-7074 affects the function expand/braceExpand/ignoreMap in hyper/bin/rimraf-standalone.js.
What kind of attack does CVE-2025-7074 facilitate?
CVE-2025-7074 can lead to inefficient regular expression complexity, potentially allowing Denial of Service conditions.
Which versions of Vercel Hyper are vulnerable to CVE-2025-7074?
Vercel Hyper versions up to and including 3.4.1 are vulnerable to CVE-2025-7074.