A denial-of-service (infinite loop) can occur in text() / textSync() when both:
- whitespaceBreak: true is set, and
- width is set smaller than the rendered width of a single FIGlet character.
Under these conditions breakWord() could never find a valid break point, so the word-wrapping loop in generateFigTextLines() never terminated. This pins a CPU core and grows memory without bound, blocking the Node.js event loop.
// severityLow or Medium. Triggering requires a non-default configuration (whitespaceBreak: true) and an attacker-controlled width value reaching text()/textSync(). This library is typically used with fixed options, where this is not reachable. Applications that pass an untrusted width together with whitespaceBreak on a request path are affected.
// patchesFixed in figlet 1.11.3. breakWord() now always makes forward progress (emitting an over-wide character on its own line), and FIGlet header parsing now rejects invalid values (e.g. zero/negative height).
// workaroundsDo not expose width to untrusted input, or leave whitespaceBreak disabled (the default), or upgrade to 1.11.3.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- Attack vector
- Network
- Attack complexity
- Low
- Attack requirements
- Present
- Privileges required
- None
- User interaction
- None
- Confidentiality (vulnerable system)
- None
- Integrity (vulnerable system)
- None
- Availability (vulnerable system)
- High
- Confidentiality (subsequent systems)
- None
- Integrity (subsequent systems)
- None
- Availability (subsequent systems)
- None