Colors.js is a lightweight, widely embedded JavaScript library for terminal color output that appears in countless Node.js projects and command-line tools as a dependency. The observed vulnerability signal centers on a logic-control issue manifesting as an infinite-loop condition in the library's output-formatting routine, which could affect any downstream application that processes untrusted or malformed input through the library. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Colors.Js Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23567HIGH The package colors after 1.4.0 are vulnerable to Denial of Service (DoS) that was introduced through an infinite loop in the americanFlag module. Unfortunately this appears to have | Jan 14, 2022 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Colors.Js Project.
Media articles that mention a CVE ID that affects a product developed by Colors.Js Project — matched by CVE ID, not by vendor name.