(Note it's a CVE-2020 ID, but it was only published in 2023):
VisualEditor bundles a copy of PapaParse (lib/ve/lib/papaparse/papaparse.js).
There was a report about a ReDoS vulnerability for it: https://github.com/mholt/PapaParse/issues/777
The fix is https://github.com/mholt/PapaParse/commit/235a12758cd77266d2e98fd715f53536b34ad621
We should include the patch (or upgrade to 5.3.0, didn't study the other changes between 5.1.0 and 5.3.0)