GHSA-62ch-8vmq-8xm7High
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
🔗 CVE IDs covered (1)
📋 Description
Impact
A denial-of-service (infinite loop) can occur in text() / textSync() when
both:
whitespaceBreak: trueis set, andwidthis set smaller than the rendered width of a single FIGlet character. Under these conditionsbreakWord()could never find a valid break point, so the word-wrapping loop ingenerateFigTextLines()never terminated. This pins a CPU core and grows memory without bound, blocking the Node.js event loop.
Severity
Low or Medium. Triggering requires a non-default configuration (whitespaceBreak: true) and
an attacker-controlled width value reaching text()/textSync(). This library is typically
used with fixed options, where this is not
reachable. Applications that pass an untrusted width together with
whitespaceBreak on a request path are affected.
Patches
Fixed in figlet 1.11.3. breakWord() now always makes forward progress
(emitting an over-wide character on its own line), and FIGlet header parsing now
rejects invalid values (e.g. zero/negative height).
Workarounds
Do not expose width to untrusted input, or leave whitespaceBreak disabled
(the default), or upgrade to 1.11.3.
🎯 Affected products1
- npm/figlet:< 1.11.3
🔗 References (5)
- https://github.com/patorjk/figlet.js/security/advisories/GHSA-62ch-8vmq-8xm7
- https://nvd.nist.gov/vuln/detail/CVE-2026-96780
- https://github.com/patorjk/figlet.js/pull/169
- https://github.com/patorjk/figlet.js/commit/cb2839d0e53aeafbd361e9587abc72e49e41cbb3
- https://github.com/advisories/GHSA-62ch-8vmq-8xm7