string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.
{ "github_reviewed_at": "2025-06-30T21:39:23Z", "severity": "LOW", "nvd_published_at": "2025-06-30T17:15:32Z", "cwe_ids": [ "CWE-1333" ], "github_reviewed": true }