Medium · 6.0 Node.js & npm GHSA-vfj7-8cjw-p6xm CVE-2026-93687
braces ≤ 3.0.3: Stack-Exhaustion Denial of Service via Deeply Nested Brace Patterns
A vulnerability in the braces npm package (versions up to and including 3.0.3) allows attackers to crash Node.js processes by supplying deeply nested brace patterns that exhaust the call stack. No fix is currently available.
AI summary
A denial-of-service vulnerability, tracked as CVE-2026-93687 (GHSA-vfj7-8cjw-p6xm), has been identified in the braces npm package. The issue affects all versions up to and including 3.0.3 and stems from recursive AST walking logic that lacks depth guards. An attacker who can submit a crafted brace pattern to an application using this library can crash the underlying Node.js process. As of publication, no fixed version is available.
What Happened
A stack overflow vulnerability was identified in the braces npm package. The package's recursive AST (abstract syntax tree) walkers, used to parse brace expansion patterns, do not include depth guards. By submitting a deeply nested brace pattern that stays under the character limit, an attacker can cause the recursion to exhaust the call stack, resulting in an uncaught RangeError that terminates the Node.js process.
Technical Cause
The root cause is uncontrolled recursion (CWE-674) in braces' pattern-parsing code. Because the recursive walkers do not enforce a maximum nesting depth, a pattern can be crafted with enough nested levels to overflow the call stack before hitting any character-length restriction, triggering a crash rather than a graceful error.
Why It Matters
Because the vulnerability can be triggered without authentication and without user interaction, any application that passes attacker-controlled input into braces' pattern parsing is at risk of a denial-of-service condition. A successful trigger crashes the Node.js process, which can disrupt service availability for affected applications.
Who Is Affected
Any project depending on the braces npm package at version 3.0.3 or earlier is affected, including applications or libraries that pass external or user-supplied strings into braces for pattern expansion.
Affected Versions
All versions of braces from the initial release (0) through 3.0.3 are affected.
Fixes and Mitigation
No fixed version has been published for this vulnerability at the time of writing. Site owners and developers should monitor the GitHub Advisory Database (GHSA-vfj7-8cjw-p6xm) and the braces npm package page for an update that introduces depth guards in the AST walkers.
Recommended Action
Until a fix is released, avoid passing untrusted or externally-controlled input directly into braces pattern-matching functions. Where possible, implement application-level input validation to reject deeply nested or suspiciously structured brace patterns before they reach the library. Monitor for a patched release and apply it promptly once available.
PatchBriefing score
6.0 / 10 · Medium
Official CVSS: 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Why this score
This vulnerability received a Patchwire score of 6 out of 10. The score reflects a CVSS base score of 8.7, contributing the majority of the weight, combined with the fact that the vulnerability can be triggered remotely without authentication (unauthenticated_remote) and without user interaction (no_user_interaction). The lack of a currently available fix (no_fix_available) adds further weight. There is no evidence of known exploitation in the wild, no public exploit code, and no EPSS score is available, which limits the overall score despite the high CVSS base rating.
Affected versions
- braces <= 3.0.3
- vulnerable
Reported fixes
No fixed version has been published for this vulnerability at the time of writing. Site owners and developers should monitor the GitHub Advisory Database (GHSA-vfj7-8cjw-p6xm) and the braces npm package page for an update that introduces depth guards in the AST walkers.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email