Withdrwn Advisory: microlight.js has a null pointer dereference vulnerability
Low severity
GitHub Reviewed
Published
Jun 17, 2025
to the GitHub Advisory Database
•
Updated Jun 18, 2025
Withdrawn
This advisory was withdrawn on Jun 18, 2025
Description
Published by the National Vulnerability Database
Jun 17, 2025
Published to the GitHub Advisory Database
Jun 17, 2025
Reviewed
Jun 17, 2025
Withdrawn
Jun 18, 2025
Last updated
Jun 18, 2025
Withdrawn Advisory
This advisory has been withdrawn because a website owner has to set CSS color values. The proof of concept doesn't demonstrate how a malicious user who is not the website owner can cause an application crash. This link has been maintained to preserve external references.
Original Description
A null pointer dereference vulnerability was discovered in microlight.js (version 0.0.7), a lightweight syntax highlighting library. When processing elements with non-standard CSS color values, the library fails to validate the result of a regular expression match before accessing its properties, leading to an uncaught TypeError and potential application crash.
References