CVE-2025-6493: CodeMirror Markdown Mode markdown.js redos
A weakness has been identified in CodeMirror up to 5.65.20. Affected is an unknown function of the file mode/markdown/markdown.js of the component Markdown Mode. This manipulation causes inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. Upgrading to version 6.0 is able to address this issue. You should upgrade the affected component. Not all code samples mentioned in the GitHub issue can be found. The repository mentions, that "CodeMirror 6 exists, and is [...] much more actively maintained."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6493?
CVE-2025-6493 is classified as a problematic vulnerability due to inefficient regular expression complexity.
How do I fix CVE-2025-6493?
To mitigate CVE-2025-6493, upgrade to a version of CodeMirror newer than 5.17.0.
What versions of CodeMirror are affected by CVE-2025-6493?
CVE-2025-6493 affects CodeMirror versions up to and including 5.17.0.
What component of CodeMirror is vulnerable in CVE-2025-6493?
The vulnerability in CVE-2025-6493 is found in the file mode/markdown/markdown.js of the Markdown Mode component.
What type of issue is associated with CVE-2025-6493?
CVE-2025-6493 is associated with a performance issue due to inefficient regular expression complexity.