CVE-2025-7074: Vercel Hyper

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the file hyper/bin/rimraf-standalone.js. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Affected products

  • Vercel Hyper: up to and including 3.4.1

Published 2025-07-05. Last modified 2026-06-17.