-
CVSS Score
-The GHSL-2020-290 advisory explicitly identifies URL validation regex patterns in the Abide form validation component as vulnerable. The provided PoC demonstrates ReDoS by inputting a URL with repeated apostrophes, which targets the URL validator. Foundation's Abide module handles form validation, and its URL validation regex is located in 'js/foundation.abide.js'. The confidence is high because the advisory directly links the vulnerability to Abide's URL validation and provides a reproducible exploit.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| foundation-sites | npm | <= 6.3.3 |
Ongoing coverage of React2Shell