node-sass is a Node.js bindings package for libsass.
Affected versions of this package are vulnerable to Uncontrolled Recursion. There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
node-sass is affected by this vulnerability due to its bundled usage of
node-sass to version 4.8.0 or higher.