{"id":"CVE-2025-5891","aliases":["GHSA-x5gf-qvw8-r2rm"],"url":"https://o3.security/vulnerability/CVE-2025-5891","summary":"Unitech pm2 Config.js redos","details":"A vulnerability classified as problematic was found in Unitech pm2 up to 6.0.6. This vulnerability affects unknown code of the file /lib/tools/Config.js. The manipulation leads to inefficient regular expression complexity. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.","published":"2025-06-09T19:00:16.482Z","modified":"2026-08-12T03:51:48.425379696Z","cvss":null,"epss":{"score":0.00605,"percentile":0.46379,"asOf":"2026-08-26"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"pm2","fixedVersion":"7.0.0"}],"fix":{"url":"https://github.com/Unitech/pm2/pull/5971","label":"Unitech/pm2#5971"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5891.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-5891"},{"type":"ADVISORY","url":"https://vuldb.com/?id.311662"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.585750"},{"type":"REPORT","url":"https://github.com/Unitech/pm2/pull/5971"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.311662"},{"type":"EVIDENCE","url":"https://gist.github.com/mmmsssttt404/407e2ffe3e0eaa393ad923a86316a385"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.425379696Z"}}