CVE-2025-5897: Vuejs Vue CLI

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability was found in vuejs vue-cli up to 5.0.8. It has been rated as problematic. This issue affects the function HtmlPwaPlugin of the file packages/@vue/cli-plugin-pwa/lib/HtmlPwaPlugin.js of the component Markdown Code Handler. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely.

Affected products

  • Vuejs Vue CLI: up to and including 5.0.8

Published 2025-06-09. Last modified 2026-06-17.