Vulnerability on @storybook/addon-docs related with trim
See original GitHub issueI know that it is not a bug, but I need to report a vulnerability that @storybook/addon-docs has.

The following is the related dependencie tree:
@storybook/addon-docs -> @mdx-js/loader -> @mdx-js/mdx -> remark-mdx -> remark-parse -> trim 0.0.1
trim 0.0.1 has a ReDoS vulnerability
Please let me know if you need more information about this. Can you fix this vuln?
Issue Analytics
- State:
- Created 2 years ago
- Reactions:69
- Comments:42 (16 by maintainers)
Top Results From Across the Web
@storybook/addon-docs 6.2.9 vulnerabilities | Snyk
Does your project rely on vulnerable package dependencies? Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities ( ...
Read more >Vulnerability on @storybook/addon-docs related with trim ...
I know that it is not a bug, but I need to report a vulnerability that @storybook/addon-docs has. image. The following is the...
Read more >How to resolve NPM audit vulnerabilities? - Stack Overflow
After running NPM audit I have identified 5 critical issues. I have tried updating @storybook/addon-essentials ...
Read more >storybook-addon-react-docgen
React Docgen is included as part of the @storybook/addon-docs package. If you are using @storybook/addon-docs then you do not need to set up...
Read more >@storybook/addon-essentials | Yarn - Package Manager
Important: This documentation covers modern versions of Yarn. For 1.x docs, see classic.yarnpkg.com. Yarn.
Read more >
Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free
Top Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found

Any news on fixing this vulnerability?
Yup. On it!! @charkour