Skip to content

CVE-2026-5986 on js-video-url-parser #4960

@zbeyens

Description

@zbeyens

Discussed in #4958

Originally posted by suiramdev April 24, 2026
There is a vulnerability of ReDoS in one of the packages @platejs/media use: https://advisories.gitlab.com/npm/js-video-url-parser/CVE-2026-5986/.

This involves in audit failing, causing the CI pipelines to fail on all apps.

I don't think it is reasonable for the library to use a 5years old outdated library, we should move on something more stable, unless the fix issued https://github.com/Zod-/jsVideoUrlParser/pull/122 is merged

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency filesecurityPull requests that address a security vulnerability

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions