Chaijs maintains a focused set of JavaScript testing and assertion utilities, with observed vulnerabilities concentrating in helper libraries such as get-func-name that are embedded across testing environments and development pipelines. The durable signal centers on resource-consumption issues stemming from inefficient regular expression patterns and uncontrolled input processing, characteristic of utility libraries that parse or reflect on function and object metadata. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chaijs over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-43646HIGH get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial | Sep 27, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chaijs.
Media articles that mention a CVE ID that affects a product developed by Chaijs — matched by CVE ID, not by vendor name.