{"id":"GHSA-64x7-m7rh-9m83","summary":"Withdrawn Advisory: microlight.js has a null pointer dereference vulnerability","details":"## Withdrawn Advisory\nThis advisory has been withdrawn because a website owner has to set CSS color values. The proof of concept doesn't demonstrate how a malicious user who is not the website owner can cause an application crash. This link has been maintained to preserve external references.\n\n## Original Description\nA null pointer dereference vulnerability was discovered in microlight.js (version 0.0.7), a lightweight syntax highlighting library. When processing elements with non-standard CSS color values, the library fails to validate the result of a regular expression match before accessing its properties, leading to an uncaught TypeError and potential application crash.","aliases":["CVE-2025-45525"],"modified":"2026-09-10T03:50:24.889444917Z","published":"2025-06-17T21:32:30Z","withdrawn":"2025-06-18T18:46:37Z","database_specific":{"cwe_ids":["CWE-476"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2025-06-17T22:36:31Z","nvd_published_at":"2025-06-17T20:15:32Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-45525"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/5730"},{"type":"WEB","url":"https://gist.github.com/Rootingg/843368931f70886bed3cf982f10a4424"},{"type":"PACKAGE","url":"https://github.com/asvd/microlight"}],"affected":[{"package":{"name":"microlight","ecosystem":"npm","purl":"pkg:npm/microlight"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.0.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-64x7-m7rh-9m83/GHSA-64x7-m7rh-9m83.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}