Vulnerability GHSA-62ch-8vmq-8xm7
Summary
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
Details
Impact
A denial-of-service (infinite loop) can occur in text() / textSync() when both:
whitespaceBreak: trueis set, andwidthis set smaller than the rendered width of a single FIGlet character. Under these conditionsbreakWord()could never find a valid break point, so the word-wrapping loop ingenerateFigTextLines()never terminated. This pins a CPU core and grows memory without bound, blocking the Node.js event loop.
Severity
Low or Medium. Triggering requires a non-default configuration (whitespaceBreak: true) and an attacker-controlled width value reaching text()/textSync(). This library is typically used with fixed options, where this is not reachable. Applications that pass an untrusted width together with whitespaceBreak on a request path are affected.
Patches
Fixed in figlet 1.11.3. breakWord() now always makes forward progress (emitting an over-wide character on its own line), and FIGlet header parsing now rejects invalid values (e.g. zero/negative height).
Workarounds
Do not expose width to untrusted input, or leave whitespaceBreak disabled (the default), or upgrade to 1.11.3.