Skip to content

chore(deps): update dependency figlet to v1.11.3 [security] - #1898

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-figlet-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-figlet-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
figlet 1.7.0 → 1.11.3 age confidence

figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width

CVE-2026-96780 / GHSA-62ch-8vmq-8xm7

More information

Details

Impact

A denial-of-service (infinite loop) can occur in text() / textSync() when
both:

  • whitespaceBreak: true is set, and
  • width is set smaller than the rendered width of a single FIGlet character.
    Under these conditions breakWord() could never find a valid break point, so the
    word-wrapping loop in generateFigTextLines() never terminated. This pins a CPU
    core and grows memory without bound, blocking the Node.js event loop.
Severity

Low or Medium. Triggering requires a non-default configuration (whitespaceBreak: true) and
an attacker-controlled width value reaching text()/textSync(). This library is typically
used with fixed options, where this is not
reachable. Applications that pass an untrusted width together with
whitespaceBreak on a request path are affected.

Patches

Fixed in figlet 1.11.3. breakWord() now always makes forward progress
(emitting an over-wide character on its own line), and FIGlet header parsing now
rejects invalid values (e.g. zero/negative height).

Workarounds

Do not expose width to untrusted input, or leave whitespaceBreak disabled
(the default), or upgrade to 1.11.3.

Severity

  • CVSS Score: 8.2 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

patorjk/figlet.js (figlet)

v1.11.3: 1.11.3

Compare Source

Bug fix for invalid input that can lead to infinite loop.

v1.11.2

Compare Source

v1.11.1

Compare Source

v1.11.0

Compare Source

Added Future Thin and Future Smooth fonts.

v1.10.0

Compare Source

  • Added the fonts: Classy, Coder Mini, and Font Font.
  • Renamed "ANSI-Compact" to "ANSI Compact" (with backward compatibility).
  • Fixed the "U" characters in the "Isometric 4" font.

v1.9.4

Compare Source

  • Added the ANSI-Compact font
  • Some adjustments for older versions of Node (#​146)

v1.9.3

Compare Source

  • Type fix for figlet module base call (when calling figlet as shorthand for figlet.text)

v1.9.2

Compare Source

  • Fixed types for TypeScript when run with Node.js.

v1.9.1

Compare Source

Wrapped the structuredClone call in an if statement for older versions of node.

v1.9.0

Compare Source

  • Refactored library to use TypeScript and to use modern tooling (instead of grunt, this project now uses vite).
  • Ensured support for both ES modules and CommonJS modules.
  • Added support for Toilet fonts:
    • ASCII 12
    • ASCII 9
    • Big ASCII 12
    • Big ASCII 9
    • Big Mono 12
    • Big Mono 9
    • Circle
    • Emboss
    • Emboss 2
    • Future
    • Letter
    • Mono 12
    • Mono 9
    • Pagga
    • Rebel
    • Small ASCII 12
    • Small ASCII 9
    • Small Block
    • Small Mono 12
    • Small Mono 9
    • Tmplr
    • WideTerm
  • Added these other new fonts:
    • Babyface Lame
    • Babyface Leet
    • Upside Down Text
  • Fixed encoding for Konto and Konto Slant.
  • Made bin/index.js more usable so the figlet-cli library isn't necessary.
  • Added a "fonts" call for the browser version of the code.
  • Added support the "fontPath" for node.js usage (that should fix the bugs people see related to font files not being found - as they can set the directory to whatever they want).
  • Fixed minor bugs.
  • Added more tests (npm run test).

v1.8.2

Compare Source

v1.8.1

Compare Source

v1.8.0

Compare Source

  • Added support for promises to various methods (#​129), thanks to @​jcubic
  • Added 5 new fonts: DiamFont, RubiFont, CosMike2, BlurVision ASCII, and Shaded Blocky

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Deploying it-tools-legacy with  Cloudflare Pages  Cloudflare Pages

Latest commit: d622961
Status:🚫  Build failed.

View logs

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying it-tools with  Cloudflare Pages  Cloudflare Pages

Latest commit: d622961
Status:🚫  Build failed.

View logs

@sonarqubecloud

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants