cbcvebase.

Debug Project Debug vulnerabilities

3 known vulnerabilities affecting debug_project/debug.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2025-59144P3HIGH≥ 4.4.2, < 4.4.32025-09-15
CVE-2025-59144 [HIGH] CWE-506 [email protected] contains malware after npm account takeover [email protected] contains malware after npm account takeover ### Impact On 8 September 2025, the npm publishing account for `debug` was taken over after a phishing attack. Version `4.4.2` was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local envi
ghsaosv
CVE-2017-20165P3HIGHCVSS 7.5fixed in 2.6.9≥ 3.0.0, < 3.1.02023-01-09
CVE-2017-20165 [HIGH] CWE-1333 CVE-2017-20165: A vulnerability classified as problematic has been found in debug-js debug up to 3.0.x. This affects A vulnerability classified as problematic has been found in debug-js debug up to 3.0.x. This affects the function useColors of the file src/node.js. The manipulation of the argument str leads to inefficient regular expression complexity. Upgrading to version 3.1.0 is able to address this issue. The identifier of the patch is c38a0166c266a679c8de012d4
ghsanvdosv
CVE-2017-16137P4MEDIUMCVSS 5.3≥ 2.0.0, < 2.6.9≥ 3.0.0, < 3.1.02018-06-07
CVE-2017-16137 [MEDIUM] CWE-400 CVE-2017-16137: The debug module is vulnerable to regular expression denial of service when untrusted user input is The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.
ghsanvdosv
Debug Project Debug vulnerabilities | cvebase