fix(utils): fix polynomial backtracking in ansiRegex - #40762

Merged
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos
May 11, 2026
Merged

fix(utils): fix polynomial backtracking in ansiRegex#40762
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos

Conversation

@SebTardif

@SebTardifSebastien Tardif (SebTardif) commented May 10, 2026

Copy link
Copy Markdown
Contributor

Summary

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking on crafted input. A payload of \x1b[ + 50,000 semicolons takes 3.1 seconds; 100,000 semicolons takes 12.6 seconds.

This is the same class of vulnerability as CVE-2021-3807 (CVSS 7.5) in the ansi-regex npm package, fixed in chalk/ansi-regex#37. Playwright's regex is a hand-rolled copy of the same pattern.

Root cause

The character class [[\]()#;?]* includes ;, and the subsequent parameter group (?:;[-a-zA-Z\d\/#&.:=?%@~_]*)* also starts with ;. When the overall match fails, the regex engine tries all possible ways to split runs of semicolons between the two groups, producing O(n^2) backtracking.

Attack vectors

  1. Shared HTML test reports (browser DoS): A test outputs the crafted payload to stderr. CI generates an HTML report. When a reviewer opens the report and clicks on the failing test, stripAnsiEscapes runs in the browser on the stdout/stderr body (testResultView.tsx), freezing the tab for 12+ seconds.

  2. CI reporter DoS: The JUnit and GitHub reporters call stripAnsiEscapes on error messages and stdout/stderr during report generation. A malicious test freezes the reporter process, blocking CI.

  3. MCP server DoS: The MCP test streams process test output through stripAnsiEscapes (streams.ts). A crafted test output freezes the MCP server.

Fix

Remove ; from [[\]()#;?]* (changed to [[\]()#?]*) to eliminate the ambiguity. Relax \d{1,4} to \d{0,4} so that empty parameters like ESC[;H (cursor home with default params) still parse correctly. Also fixed the duplicate regex in tests/config/utils.ts.

Verification

InputBeforeAfter
50K semicolons3,086ms<1ms
\x1b[31mred\x1b[0mredred
\x1b[;H````
\x1b[38;2;255;0;0m````

Origin

The regex was introduced in #3575 (2020-08-22). The overlapping character classes have been present since the original commit.

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking
on inputs like ESC[ followed by many semicolons. The root cause
is that semicolons can be matched by both the initial character
class [[\]()#;?]* and the parameter group (?:;...)*. Remove
semicolons from the initial group and relax \d{1,4} to \d{0,4}
so that empty parameters (e.g. ESC[;H) still parse correctly.
Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
@pavelfeldman

Copy link
Copy Markdown
Member

Note: Security framing is overstated, but doesn't undermine the fix. All three "attack vectors" require an attacker who can already inject arbitrary stdout/stderr content into a test run — which means they're already executing code in the test sandbox. The HTML-report scenario (renderer freezes for a reviewer's tab) is the most plausible, but it still presumes an attacker who controls test output. CVE-2021-3807 had higher impact because ansi-regex is a transitive dependency of huge swaths of the npm ecosystem; that doesn't transfer cleanly here.

@github-actions

This comment has been minimized.

@github-actions

This comment has been minimized.

const start = performance.now();
const result = stripAnsiEscapes(payload);
const elapsed = performance.now() - start;
expect(elapsed).toBeLessThan(100);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will never fly on the bots, can't compare time on CI.

@SebTardif

Copy link
Copy Markdown
ContributorAuthor

Removed the timing assertion. The test still verifies the regex doesn't hang - if polynomial backtracking were present, the test would timeout rather than fail a timing check.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "MCP"

5 failed
❌ [chrome] › mcp/annotate.spec.ts:57 › should capture multiple screenshots in one annotation @mcp-windows-latest-chrome
❌ [chrome] › mcp/annotate.spec.ts:110 › should abort annotation when last screenshot is removed @mcp-windows-latest-chrome
❌ [firefox] › mcp/cli-devtools.spec.ts:217 › video-start-stop @mcp-windows-latest-firefox
❌ [firefox] › mcp/cli-devtools.spec.ts:231 › video-chapter @mcp-windows-latest-firefox
❌ [firefox] › mcp/tracing.spec.ts:54 › check that trace is saved with browser_start_tracing (no output dir) @mcp-windows-latest-firefox

7052 passed, 1068 skipped


Merge workflow run.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "tests 1"

2 flaky⚠️ [chromium-library] › library/video.spec.ts:719 › screencast › should work with video+trace `@chromium-ubuntu-22.04-arm-node20`
⚠️ [chromium-library] › library/popup.spec.ts:261 › should not throw when click closes popup `@chromium-ubuntu-22.04-node20`

41746 passed, 850 skipped


Merge workflow run.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@SebTardif@pavelfeldman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(utils): fix polynomial backtracking in ansiRegex - #40762

Merged
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos
May 11, 2026
Merged

fix(utils): fix polynomial backtracking in ansiRegex#40762
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos

Conversation

@SebTardif

@SebTardifSebastien Tardif (SebTardif) commented May 10, 2026

Copy link
Copy Markdown
Contributor

Summary

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking on crafted input. A payload of \x1b[ + 50,000 semicolons takes 3.1 seconds; 100,000 semicolons takes 12.6 seconds.

This is the same class of vulnerability as CVE-2021-3807 (CVSS 7.5) in the ansi-regex npm package, fixed in chalk/ansi-regex#37. Playwright's regex is a hand-rolled copy of the same pattern.

Root cause

The character class [[\]()#;?]* includes ;, and the subsequent parameter group (?:;[-a-zA-Z\d\/#&.:=?%@~_]*)* also starts with ;. When the overall match fails, the regex engine tries all possible ways to split runs of semicolons between the two groups, producing O(n^2) backtracking.

Attack vectors

  1. Shared HTML test reports (browser DoS): A test outputs the crafted payload to stderr. CI generates an HTML report. When a reviewer opens the report and clicks on the failing test, stripAnsiEscapes runs in the browser on the stdout/stderr body (testResultView.tsx), freezing the tab for 12+ seconds.

  2. CI reporter DoS: The JUnit and GitHub reporters call stripAnsiEscapes on error messages and stdout/stderr during report generation. A malicious test freezes the reporter process, blocking CI.

  3. MCP server DoS: The MCP test streams process test output through stripAnsiEscapes (streams.ts). A crafted test output freezes the MCP server.

Fix

Remove ; from [[\]()#;?]* (changed to [[\]()#?]*) to eliminate the ambiguity. Relax \d{1,4} to \d{0,4} so that empty parameters like ESC[;H (cursor home with default params) still parse correctly. Also fixed the duplicate regex in tests/config/utils.ts.

Verification

InputBeforeAfter
50K semicolons3,086ms<1ms
\x1b[31mred\x1b[0mredred
\x1b[;H````
\x1b[38;2;255;0;0m````

Origin

The regex was introduced in #3575 (2020-08-22). The overlapping character classes have been present since the original commit.

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking
on inputs like ESC[ followed by many semicolons. The root cause
is that semicolons can be matched by both the initial character
class [[\]()#;?]* and the parameter group (?:;...)*. Remove
semicolons from the initial group and relax \d{1,4} to \d{0,4}
so that empty parameters (e.g. ESC[;H) still parse correctly.
Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
@pavelfeldman

Copy link
Copy Markdown
Member

Note: Security framing is overstated, but doesn't undermine the fix. All three "attack vectors" require an attacker who can already inject arbitrary stdout/stderr content into a test run — which means they're already executing code in the test sandbox. The HTML-report scenario (renderer freezes for a reviewer's tab) is the most plausible, but it still presumes an attacker who controls test output. CVE-2021-3807 had higher impact because ansi-regex is a transitive dependency of huge swaths of the npm ecosystem; that doesn't transfer cleanly here.

@github-actions

This comment has been minimized.

@github-actions

This comment has been minimized.

const start = performance.now();
const result = stripAnsiEscapes(payload);
const elapsed = performance.now() - start;
expect(elapsed).toBeLessThan(100);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will never fly on the bots, can't compare time on CI.

@SebTardif

Copy link
Copy Markdown
ContributorAuthor

Removed the timing assertion. The test still verifies the regex doesn't hang - if polynomial backtracking were present, the test would timeout rather than fail a timing check.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "MCP"

5 failed
❌ [chrome] › mcp/annotate.spec.ts:57 › should capture multiple screenshots in one annotation @mcp-windows-latest-chrome
❌ [chrome] › mcp/annotate.spec.ts:110 › should abort annotation when last screenshot is removed @mcp-windows-latest-chrome
❌ [firefox] › mcp/cli-devtools.spec.ts:217 › video-start-stop @mcp-windows-latest-firefox
❌ [firefox] › mcp/cli-devtools.spec.ts:231 › video-chapter @mcp-windows-latest-firefox
❌ [firefox] › mcp/tracing.spec.ts:54 › check that trace is saved with browser_start_tracing (no output dir) @mcp-windows-latest-firefox

7052 passed, 1068 skipped


Merge workflow run.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "tests 1"

2 flaky⚠️ [chromium-library] › library/video.spec.ts:719 › screencast › should work with video+trace `@chromium-ubuntu-22.04-arm-node20`
⚠️ [chromium-library] › library/popup.spec.ts:261 › should not throw when click closes popup `@chromium-ubuntu-22.04-node20`

41746 passed, 850 skipped


Merge workflow run.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@SebTardif@pavelfeldman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(utils): fix polynomial backtracking in ansiRegex - #40762

Merged
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos
May 11, 2026
Merged

fix(utils): fix polynomial backtracking in ansiRegex#40762
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos

Conversation

@SebTardif

@SebTardifSebastien Tardif (SebTardif) commented May 10, 2026

Copy link
Copy Markdown
Contributor

Summary

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking on crafted input. A payload of \x1b[ + 50,000 semicolons takes 3.1 seconds; 100,000 semicolons takes 12.6 seconds.

This is the same class of vulnerability as CVE-2021-3807 (CVSS 7.5) in the ansi-regex npm package, fixed in chalk/ansi-regex#37. Playwright's regex is a hand-rolled copy of the same pattern.

Root cause

The character class [[\]()#;?]* includes ;, and the subsequent parameter group (?:;[-a-zA-Z\d\/#&.:=?%@~_]*)* also starts with ;. When the overall match fails, the regex engine tries all possible ways to split runs of semicolons between the two groups, producing O(n^2) backtracking.

Attack vectors

  1. Shared HTML test reports (browser DoS): A test outputs the crafted payload to stderr. CI generates an HTML report. When a reviewer opens the report and clicks on the failing test, stripAnsiEscapes runs in the browser on the stdout/stderr body (testResultView.tsx), freezing the tab for 12+ seconds.

  2. CI reporter DoS: The JUnit and GitHub reporters call stripAnsiEscapes on error messages and stdout/stderr during report generation. A malicious test freezes the reporter process, blocking CI.

  3. MCP server DoS: The MCP test streams process test output through stripAnsiEscapes (streams.ts). A crafted test output freezes the MCP server.

Fix

Remove ; from [[\]()#;?]* (changed to [[\]()#?]*) to eliminate the ambiguity. Relax \d{1,4} to \d{0,4} so that empty parameters like ESC[;H (cursor home with default params) still parse correctly. Also fixed the duplicate regex in tests/config/utils.ts.

Verification

InputBeforeAfter
50K semicolons3,086ms<1ms
\x1b[31mred\x1b[0mredred
\x1b[;H````
\x1b[38;2;255;0;0m````

Origin

The regex was introduced in #3575 (2020-08-22). The overlapping character classes have been present since the original commit.

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking
on inputs like ESC[ followed by many semicolons. The root cause
is that semicolons can be matched by both the initial character
class [[\]()#;?]* and the parameter group (?:;...)*. Remove
semicolons from the initial group and relax \d{1,4} to \d{0,4}
so that empty parameters (e.g. ESC[;H) still parse correctly.
Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
@pavelfeldman

Copy link
Copy Markdown
Member

Note: Security framing is overstated, but doesn't undermine the fix. All three "attack vectors" require an attacker who can already inject arbitrary stdout/stderr content into a test run — which means they're already executing code in the test sandbox. The HTML-report scenario (renderer freezes for a reviewer's tab) is the most plausible, but it still presumes an attacker who controls test output. CVE-2021-3807 had higher impact because ansi-regex is a transitive dependency of huge swaths of the npm ecosystem; that doesn't transfer cleanly here.

@github-actions

This comment has been minimized.

@github-actions

This comment has been minimized.

const start = performance.now();
const result = stripAnsiEscapes(payload);
const elapsed = performance.now() - start;
expect(elapsed).toBeLessThan(100);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will never fly on the bots, can't compare time on CI.

@SebTardif

Copy link
Copy Markdown
ContributorAuthor

Removed the timing assertion. The test still verifies the regex doesn't hang - if polynomial backtracking were present, the test would timeout rather than fail a timing check.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "MCP"

5 failed
❌ [chrome] › mcp/annotate.spec.ts:57 › should capture multiple screenshots in one annotation @mcp-windows-latest-chrome
❌ [chrome] › mcp/annotate.spec.ts:110 › should abort annotation when last screenshot is removed @mcp-windows-latest-chrome
❌ [firefox] › mcp/cli-devtools.spec.ts:217 › video-start-stop @mcp-windows-latest-firefox
❌ [firefox] › mcp/cli-devtools.spec.ts:231 › video-chapter @mcp-windows-latest-firefox
❌ [firefox] › mcp/tracing.spec.ts:54 › check that trace is saved with browser_start_tracing (no output dir) @mcp-windows-latest-firefox

7052 passed, 1068 skipped


Merge workflow run.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "tests 1"

2 flaky⚠️ [chromium-library] › library/video.spec.ts:719 › screencast › should work with video+trace `@chromium-ubuntu-22.04-arm-node20`
⚠️ [chromium-library] › library/popup.spec.ts:261 › should not throw when click closes popup `@chromium-ubuntu-22.04-node20`

41746 passed, 850 skipped


Merge workflow run.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@SebTardif@pavelfeldman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(utils): fix polynomial backtracking in ansiRegex - #40762

Merged
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos
May 11, 2026
Merged

fix(utils): fix polynomial backtracking in ansiRegex#40762
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos

Conversation

@SebTardif

@SebTardifSebastien Tardif (SebTardif) commented May 10, 2026

Copy link
Copy Markdown
Contributor

Summary

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking on crafted input. A payload of \x1b[ + 50,000 semicolons takes 3.1 seconds; 100,000 semicolons takes 12.6 seconds.

This is the same class of vulnerability as CVE-2021-3807 (CVSS 7.5) in the ansi-regex npm package, fixed in chalk/ansi-regex#37. Playwright's regex is a hand-rolled copy of the same pattern.

Root cause

The character class [[\]()#;?]* includes ;, and the subsequent parameter group (?:;[-a-zA-Z\d\/#&.:=?%@~_]*)* also starts with ;. When the overall match fails, the regex engine tries all possible ways to split runs of semicolons between the two groups, producing O(n^2) backtracking.

Attack vectors

  1. Shared HTML test reports (browser DoS): A test outputs the crafted payload to stderr. CI generates an HTML report. When a reviewer opens the report and clicks on the failing test, stripAnsiEscapes runs in the browser on the stdout/stderr body (testResultView.tsx), freezing the tab for 12+ seconds.

  2. CI reporter DoS: The JUnit and GitHub reporters call stripAnsiEscapes on error messages and stdout/stderr during report generation. A malicious test freezes the reporter process, blocking CI.

  3. MCP server DoS: The MCP test streams process test output through stripAnsiEscapes (streams.ts). A crafted test output freezes the MCP server.

Fix

Remove ; from [[\]()#;?]* (changed to [[\]()#?]*) to eliminate the ambiguity. Relax \d{1,4} to \d{0,4} so that empty parameters like ESC[;H (cursor home with default params) still parse correctly. Also fixed the duplicate regex in tests/config/utils.ts.

Verification

InputBeforeAfter
50K semicolons3,086ms<1ms
\x1b[31mred\x1b[0mredred
\x1b[;H````
\x1b[38;2;255;0;0m````

Origin

The regex was introduced in #3575 (2020-08-22). The overlapping character classes have been present since the original commit.

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking
on inputs like ESC[ followed by many semicolons. The root cause
is that semicolons can be matched by both the initial character
class [[\]()#;?]* and the parameter group (?:;...)*. Remove
semicolons from the initial group and relax \d{1,4} to \d{0,4}
so that empty parameters (e.g. ESC[;H) still parse correctly.
Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
@pavelfeldman

Copy link
Copy Markdown
Member

Note: Security framing is overstated, but doesn't undermine the fix. All three "attack vectors" require an attacker who can already inject arbitrary stdout/stderr content into a test run — which means they're already executing code in the test sandbox. The HTML-report scenario (renderer freezes for a reviewer's tab) is the most plausible, but it still presumes an attacker who controls test output. CVE-2021-3807 had higher impact because ansi-regex is a transitive dependency of huge swaths of the npm ecosystem; that doesn't transfer cleanly here.

@github-actions

This comment has been minimized.

@github-actions

This comment has been minimized.

const start = performance.now();
const result = stripAnsiEscapes(payload);
const elapsed = performance.now() - start;
expect(elapsed).toBeLessThan(100);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will never fly on the bots, can't compare time on CI.

@SebTardif

Copy link
Copy Markdown
ContributorAuthor

Removed the timing assertion. The test still verifies the regex doesn't hang - if polynomial backtracking were present, the test would timeout rather than fail a timing check.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "MCP"

5 failed
❌ [chrome] › mcp/annotate.spec.ts:57 › should capture multiple screenshots in one annotation @mcp-windows-latest-chrome
❌ [chrome] › mcp/annotate.spec.ts:110 › should abort annotation when last screenshot is removed @mcp-windows-latest-chrome
❌ [firefox] › mcp/cli-devtools.spec.ts:217 › video-start-stop @mcp-windows-latest-firefox
❌ [firefox] › mcp/cli-devtools.spec.ts:231 › video-chapter @mcp-windows-latest-firefox
❌ [firefox] › mcp/tracing.spec.ts:54 › check that trace is saved with browser_start_tracing (no output dir) @mcp-windows-latest-firefox

7052 passed, 1068 skipped


Merge workflow run.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "tests 1"

2 flaky⚠️ [chromium-library] › library/video.spec.ts:719 › screencast › should work with video+trace `@chromium-ubuntu-22.04-arm-node20`
⚠️ [chromium-library] › library/popup.spec.ts:261 › should not throw when click closes popup `@chromium-ubuntu-22.04-node20`

41746 passed, 850 skipped


Merge workflow run.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@SebTardif@pavelfeldman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(utils): fix polynomial backtracking in ansiRegex - #40762

Merged
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos
May 11, 2026
Merged

fix(utils): fix polynomial backtracking in ansiRegex#40762
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos

Conversation

@SebTardif

@SebTardifSebastien Tardif (SebTardif) commented May 10, 2026

Copy link
Copy Markdown
Contributor

Summary

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking on crafted input. A payload of \x1b[ + 50,000 semicolons takes 3.1 seconds; 100,000 semicolons takes 12.6 seconds.

This is the same class of vulnerability as CVE-2021-3807 (CVSS 7.5) in the ansi-regex npm package, fixed in chalk/ansi-regex#37. Playwright's regex is a hand-rolled copy of the same pattern.

Root cause

The character class [[\]()#;?]* includes ;, and the subsequent parameter group (?:;[-a-zA-Z\d\/#&.:=?%@~_]*)* also starts with ;. When the overall match fails, the regex engine tries all possible ways to split runs of semicolons between the two groups, producing O(n^2) backtracking.

Attack vectors

  1. Shared HTML test reports (browser DoS): A test outputs the crafted payload to stderr. CI generates an HTML report. When a reviewer opens the report and clicks on the failing test, stripAnsiEscapes runs in the browser on the stdout/stderr body (testResultView.tsx), freezing the tab for 12+ seconds.

  2. CI reporter DoS: The JUnit and GitHub reporters call stripAnsiEscapes on error messages and stdout/stderr during report generation. A malicious test freezes the reporter process, blocking CI.

  3. MCP server DoS: The MCP test streams process test output through stripAnsiEscapes (streams.ts). A crafted test output freezes the MCP server.

Fix

Remove ; from [[\]()#;?]* (changed to [[\]()#?]*) to eliminate the ambiguity. Relax \d{1,4} to \d{0,4} so that empty parameters like ESC[;H (cursor home with default params) still parse correctly. Also fixed the duplicate regex in tests/config/utils.ts.

Verification

InputBeforeAfter
50K semicolons3,086ms<1ms
\x1b[31mred\x1b[0mredred
\x1b[;H````
\x1b[38;2;255;0;0m````

Origin

The regex was introduced in #3575 (2020-08-22). The overlapping character classes have been present since the original commit.

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking
on inputs like ESC[ followed by many semicolons. The root cause
is that semicolons can be matched by both the initial character
class [[\]()#;?]* and the parameter group (?:;...)*. Remove
semicolons from the initial group and relax \d{1,4} to \d{0,4}
so that empty parameters (e.g. ESC[;H) still parse correctly.
Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
@pavelfeldman

Copy link
Copy Markdown
Member

Note: Security framing is overstated, but doesn't undermine the fix. All three "attack vectors" require an attacker who can already inject arbitrary stdout/stderr content into a test run — which means they're already executing code in the test sandbox. The HTML-report scenario (renderer freezes for a reviewer's tab) is the most plausible, but it still presumes an attacker who controls test output. CVE-2021-3807 had higher impact because ansi-regex is a transitive dependency of huge swaths of the npm ecosystem; that doesn't transfer cleanly here.

@github-actions

This comment has been minimized.

@github-actions

This comment has been minimized.

const start = performance.now();
const result = stripAnsiEscapes(payload);
const elapsed = performance.now() - start;
expect(elapsed).toBeLessThan(100);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will never fly on the bots, can't compare time on CI.

@SebTardif

Copy link
Copy Markdown
ContributorAuthor

Removed the timing assertion. The test still verifies the regex doesn't hang - if polynomial backtracking were present, the test would timeout rather than fail a timing check.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "MCP"

5 failed
❌ [chrome] › mcp/annotate.spec.ts:57 › should capture multiple screenshots in one annotation @mcp-windows-latest-chrome
❌ [chrome] › mcp/annotate.spec.ts:110 › should abort annotation when last screenshot is removed @mcp-windows-latest-chrome
❌ [firefox] › mcp/cli-devtools.spec.ts:217 › video-start-stop @mcp-windows-latest-firefox
❌ [firefox] › mcp/cli-devtools.spec.ts:231 › video-chapter @mcp-windows-latest-firefox
❌ [firefox] › mcp/tracing.spec.ts:54 › check that trace is saved with browser_start_tracing (no output dir) @mcp-windows-latest-firefox

7052 passed, 1068 skipped


Merge workflow run.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "tests 1"

2 flaky⚠️ [chromium-library] › library/video.spec.ts:719 › screencast › should work with video+trace `@chromium-ubuntu-22.04-arm-node20`
⚠️ [chromium-library] › library/popup.spec.ts:261 › should not throw when click closes popup `@chromium-ubuntu-22.04-node20`

41746 passed, 850 skipped


Merge workflow run.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@SebTardif@pavelfeldman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(utils): fix polynomial backtracking in ansiRegex - #40762

Merged
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos
May 11, 2026
Merged

fix(utils): fix polynomial backtracking in ansiRegex#40762
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos

Conversation

@SebTardif

@SebTardifSebastien Tardif (SebTardif) commented May 10, 2026

Copy link
Copy Markdown
Contributor

Summary

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking on crafted input. A payload of \x1b[ + 50,000 semicolons takes 3.1 seconds; 100,000 semicolons takes 12.6 seconds.

This is the same class of vulnerability as CVE-2021-3807 (CVSS 7.5) in the ansi-regex npm package, fixed in chalk/ansi-regex#37. Playwright's regex is a hand-rolled copy of the same pattern.

Root cause

The character class [[\]()#;?]* includes ;, and the subsequent parameter group (?:;[-a-zA-Z\d\/#&.:=?%@~_]*)* also starts with ;. When the overall match fails, the regex engine tries all possible ways to split runs of semicolons between the two groups, producing O(n^2) backtracking.

Attack vectors

  1. Shared HTML test reports (browser DoS): A test outputs the crafted payload to stderr. CI generates an HTML report. When a reviewer opens the report and clicks on the failing test, stripAnsiEscapes runs in the browser on the stdout/stderr body (testResultView.tsx), freezing the tab for 12+ seconds.

  2. CI reporter DoS: The JUnit and GitHub reporters call stripAnsiEscapes on error messages and stdout/stderr during report generation. A malicious test freezes the reporter process, blocking CI.

  3. MCP server DoS: The MCP test streams process test output through stripAnsiEscapes (streams.ts). A crafted test output freezes the MCP server.

Fix

Remove ; from [[\]()#;?]* (changed to [[\]()#?]*) to eliminate the ambiguity. Relax \d{1,4} to \d{0,4} so that empty parameters like ESC[;H (cursor home with default params) still parse correctly. Also fixed the duplicate regex in tests/config/utils.ts.

Verification

InputBeforeAfter
50K semicolons3,086ms<1ms
\x1b[31mred\x1b[0mredred
\x1b[;H````
\x1b[38;2;255;0;0m````

Origin

The regex was introduced in #3575 (2020-08-22). The overlapping character classes have been present since the original commit.

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking
on inputs like ESC[ followed by many semicolons. The root cause
is that semicolons can be matched by both the initial character
class [[\]()#;?]* and the parameter group (?:;...)*. Remove
semicolons from the initial group and relax \d{1,4} to \d{0,4}
so that empty parameters (e.g. ESC[;H) still parse correctly.
Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
@pavelfeldman

Copy link
Copy Markdown
Member

Note: Security framing is overstated, but doesn't undermine the fix. All three "attack vectors" require an attacker who can already inject arbitrary stdout/stderr content into a test run — which means they're already executing code in the test sandbox. The HTML-report scenario (renderer freezes for a reviewer's tab) is the most plausible, but it still presumes an attacker who controls test output. CVE-2021-3807 had higher impact because ansi-regex is a transitive dependency of huge swaths of the npm ecosystem; that doesn't transfer cleanly here.

@github-actions

This comment has been minimized.

@github-actions

This comment has been minimized.

const start = performance.now();
const result = stripAnsiEscapes(payload);
const elapsed = performance.now() - start;
expect(elapsed).toBeLessThan(100);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will never fly on the bots, can't compare time on CI.

@SebTardif

Copy link
Copy Markdown
ContributorAuthor

Removed the timing assertion. The test still verifies the regex doesn't hang - if polynomial backtracking were present, the test would timeout rather than fail a timing check.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "MCP"

5 failed
❌ [chrome] › mcp/annotate.spec.ts:57 › should capture multiple screenshots in one annotation @mcp-windows-latest-chrome
❌ [chrome] › mcp/annotate.spec.ts:110 › should abort annotation when last screenshot is removed @mcp-windows-latest-chrome
❌ [firefox] › mcp/cli-devtools.spec.ts:217 › video-start-stop @mcp-windows-latest-firefox
❌ [firefox] › mcp/cli-devtools.spec.ts:231 › video-chapter @mcp-windows-latest-firefox
❌ [firefox] › mcp/tracing.spec.ts:54 › check that trace is saved with browser_start_tracing (no output dir) @mcp-windows-latest-firefox

7052 passed, 1068 skipped


Merge workflow run.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "tests 1"

2 flaky⚠️ [chromium-library] › library/video.spec.ts:719 › screencast › should work with video+trace `@chromium-ubuntu-22.04-arm-node20`
⚠️ [chromium-library] › library/popup.spec.ts:261 › should not throw when click closes popup `@chromium-ubuntu-22.04-node20`

41746 passed, 850 skipped


Merge workflow run.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@SebTardif@pavelfeldman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(utils): fix polynomial backtracking in ansiRegex - #40762

Merged
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos
May 11, 2026
Merged

fix(utils): fix polynomial backtracking in ansiRegex#40762
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos

Conversation

@SebTardif

@SebTardifSebastien Tardif (SebTardif) commented May 10, 2026

Copy link
Copy Markdown
Contributor

Summary

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking on crafted input. A payload of \x1b[ + 50,000 semicolons takes 3.1 seconds; 100,000 semicolons takes 12.6 seconds.

This is the same class of vulnerability as CVE-2021-3807 (CVSS 7.5) in the ansi-regex npm package, fixed in chalk/ansi-regex#37. Playwright's regex is a hand-rolled copy of the same pattern.

Root cause

The character class [[\]()#;?]* includes ;, and the subsequent parameter group (?:;[-a-zA-Z\d\/#&.:=?%@~_]*)* also starts with ;. When the overall match fails, the regex engine tries all possible ways to split runs of semicolons between the two groups, producing O(n^2) backtracking.

Attack vectors

  1. Shared HTML test reports (browser DoS): A test outputs the crafted payload to stderr. CI generates an HTML report. When a reviewer opens the report and clicks on the failing test, stripAnsiEscapes runs in the browser on the stdout/stderr body (testResultView.tsx), freezing the tab for 12+ seconds.

  2. CI reporter DoS: The JUnit and GitHub reporters call stripAnsiEscapes on error messages and stdout/stderr during report generation. A malicious test freezes the reporter process, blocking CI.

  3. MCP server DoS: The MCP test streams process test output through stripAnsiEscapes (streams.ts). A crafted test output freezes the MCP server.

Fix

Remove ; from [[\]()#;?]* (changed to [[\]()#?]*) to eliminate the ambiguity. Relax \d{1,4} to \d{0,4} so that empty parameters like ESC[;H (cursor home with default params) still parse correctly. Also fixed the duplicate regex in tests/config/utils.ts.

Verification

InputBeforeAfter
50K semicolons3,086ms<1ms
\x1b[31mred\x1b[0mredred
\x1b[;H````
\x1b[38;2;255;0;0m````

Origin

The regex was introduced in #3575 (2020-08-22). The overlapping character classes have been present since the original commit.

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking
on inputs like ESC[ followed by many semicolons. The root cause
is that semicolons can be matched by both the initial character
class [[\]()#;?]* and the parameter group (?:;...)*. Remove
semicolons from the initial group and relax \d{1,4} to \d{0,4}
so that empty parameters (e.g. ESC[;H) still parse correctly.
Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
@pavelfeldman

Copy link
Copy Markdown
Member

Note: Security framing is overstated, but doesn't undermine the fix. All three "attack vectors" require an attacker who can already inject arbitrary stdout/stderr content into a test run — which means they're already executing code in the test sandbox. The HTML-report scenario (renderer freezes for a reviewer's tab) is the most plausible, but it still presumes an attacker who controls test output. CVE-2021-3807 had higher impact because ansi-regex is a transitive dependency of huge swaths of the npm ecosystem; that doesn't transfer cleanly here.

@github-actions

This comment has been minimized.

@github-actions

This comment has been minimized.

const start = performance.now();
const result = stripAnsiEscapes(payload);
const elapsed = performance.now() - start;
expect(elapsed).toBeLessThan(100);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will never fly on the bots, can't compare time on CI.

@SebTardif

Copy link
Copy Markdown
ContributorAuthor

Removed the timing assertion. The test still verifies the regex doesn't hang - if polynomial backtracking were present, the test would timeout rather than fail a timing check.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "MCP"

5 failed
❌ [chrome] › mcp/annotate.spec.ts:57 › should capture multiple screenshots in one annotation @mcp-windows-latest-chrome
❌ [chrome] › mcp/annotate.spec.ts:110 › should abort annotation when last screenshot is removed @mcp-windows-latest-chrome
❌ [firefox] › mcp/cli-devtools.spec.ts:217 › video-start-stop @mcp-windows-latest-firefox
❌ [firefox] › mcp/cli-devtools.spec.ts:231 › video-chapter @mcp-windows-latest-firefox
❌ [firefox] › mcp/tracing.spec.ts:54 › check that trace is saved with browser_start_tracing (no output dir) @mcp-windows-latest-firefox

7052 passed, 1068 skipped


Merge workflow run.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "tests 1"

2 flaky⚠️ [chromium-library] › library/video.spec.ts:719 › screencast › should work with video+trace `@chromium-ubuntu-22.04-arm-node20`
⚠️ [chromium-library] › library/popup.spec.ts:261 › should not throw when click closes popup `@chromium-ubuntu-22.04-node20`

41746 passed, 850 skipped


Merge workflow run.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@SebTardif@pavelfeldman
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(utils): fix polynomial backtracking in ansiRegex - #40762

Merged
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos
May 11, 2026
Merged

fix(utils): fix polynomial backtracking in ansiRegex#40762
Pavel Feldman (pavelfeldman) merged 2 commits into
microsoft:mainfrom
SebTardif:fix-ansi-regex-redos

Conversation

@SebTardif

@SebTardifSebastien Tardif (SebTardif) commented May 10, 2026

Copy link
Copy Markdown
Contributor

Summary

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking on crafted input. A payload of \x1b[ + 50,000 semicolons takes 3.1 seconds; 100,000 semicolons takes 12.6 seconds.

This is the same class of vulnerability as CVE-2021-3807 (CVSS 7.5) in the ansi-regex npm package, fixed in chalk/ansi-regex#37. Playwright's regex is a hand-rolled copy of the same pattern.

Root cause

The character class [[\]()#;?]* includes ;, and the subsequent parameter group (?:;[-a-zA-Z\d\/#&.:=?%@~_]*)* also starts with ;. When the overall match fails, the regex engine tries all possible ways to split runs of semicolons between the two groups, producing O(n^2) backtracking.

Attack vectors

  1. Shared HTML test reports (browser DoS): A test outputs the crafted payload to stderr. CI generates an HTML report. When a reviewer opens the report and clicks on the failing test, stripAnsiEscapes runs in the browser on the stdout/stderr body (testResultView.tsx), freezing the tab for 12+ seconds.

  2. CI reporter DoS: The JUnit and GitHub reporters call stripAnsiEscapes on error messages and stdout/stderr during report generation. A malicious test freezes the reporter process, blocking CI.

  3. MCP server DoS: The MCP test streams process test output through stripAnsiEscapes (streams.ts). A crafted test output freezes the MCP server.

Fix

Remove ; from [[\]()#;?]* (changed to [[\]()#?]*) to eliminate the ambiguity. Relax \d{1,4} to \d{0,4} so that empty parameters like ESC[;H (cursor home with default params) still parse correctly. Also fixed the duplicate regex in tests/config/utils.ts.

Verification

InputBeforeAfter
50K semicolons3,086ms<1ms
\x1b[31mred\x1b[0mredred
\x1b[;H````
\x1b[38;2;255;0;0m````

Origin

The regex was introduced in #3575 (2020-08-22). The overlapping character classes have been present since the original commit.

The ansiRegex used by stripAnsiEscapes has O(n^2) backtracking
on inputs like ESC[ followed by many semicolons. The root cause
is that semicolons can be matched by both the initial character
class [[\]()#;?]* and the parameter group (?:;...)*. Remove
semicolons from the initial group and relax \d{1,4} to \d{0,4}
so that empty parameters (e.g. ESC[;H) still parse correctly.
Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
@pavelfeldman

Copy link
Copy Markdown
Member

Note: Security framing is overstated, but doesn't undermine the fix. All three "attack vectors" require an attacker who can already inject arbitrary stdout/stderr content into a test run — which means they're already executing code in the test sandbox. The HTML-report scenario (renderer freezes for a reviewer's tab) is the most plausible, but it still presumes an attacker who controls test output. CVE-2021-3807 had higher impact because ansi-regex is a transitive dependency of huge swaths of the npm ecosystem; that doesn't transfer cleanly here.

@github-actions

This comment has been minimized.

@github-actions

This comment has been minimized.

const start = performance.now();
const result = stripAnsiEscapes(payload);
const elapsed = performance.now() - start;
expect(elapsed).toBeLessThan(100);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will never fly on the bots, can't compare time on CI.

@SebTardif

Copy link
Copy Markdown
ContributorAuthor

Removed the timing assertion. The test still verifies the regex doesn't hang - if polynomial backtracking were present, the test would timeout rather than fail a timing check.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "MCP"

5 failed
❌ [chrome] › mcp/annotate.spec.ts:57 › should capture multiple screenshots in one annotation @mcp-windows-latest-chrome
❌ [chrome] › mcp/annotate.spec.ts:110 › should abort annotation when last screenshot is removed @mcp-windows-latest-chrome
❌ [firefox] › mcp/cli-devtools.spec.ts:217 › video-start-stop @mcp-windows-latest-firefox
❌ [firefox] › mcp/cli-devtools.spec.ts:231 › video-chapter @mcp-windows-latest-firefox
❌ [firefox] › mcp/tracing.spec.ts:54 › check that trace is saved with browser_start_tracing (no output dir) @mcp-windows-latest-firefox

7052 passed, 1068 skipped


Merge workflow run.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "tests 1"

2 flaky⚠️ [chromium-library] › library/video.spec.ts:719 › screencast › should work with video+trace `@chromium-ubuntu-22.04-arm-node20`
⚠️ [chromium-library] › library/popup.spec.ts:261 › should not throw when click closes popup `@chromium-ubuntu-22.04-node20`

41746 passed, 850 skipped


Merge workflow run.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@SebTardif@pavelfeldman