CRITICAL9.8
GHSA-mm62-wxc8-cf7m
Code Execution Through IIFE in serialize-to-js
Quick fix
GHSA-mm62-wxc8-cf7m — serialize-to-js: upgrade to the fixed version with the command below.
npm install serialize-to-js@1.0.0Details
Affected versions of `serialize-to-js` may be vulnerable to arbitrary code execution through an Immediately Invoked Function Expression (IIFE).
## Proof of Concept ```js var payload = "{e: (function(){ eval('console.log(`exploited`)') })() }" var serialize = require('serialize-to-js'); serialize.deserialize(payload); ```
## Recommendation
Update to version 1.0.0, or later, and review [this disclaimer](https://www.npmjs.com/package/serialize-to-js#deserialize) from the author.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-5954[ADVISORY]
- https://github.com/commenthol/serialize-to-js/issues/1[WEB]
- https://github.com/commenthol/serialize-to-js/commit/1cd433960e5b9db4c0b537afb28366198a319429[WEB]
- https://github.com/advisories/GHSA-mm62-wxc8-cf7m[ADVISORY]
- https://github.com/commenthol/serialize-to-js[PACKAGE]
- https://opsecx.com/index.php/2017/02/08/exploiting-node-js-deserialization-bug-for-remote-code-execution[WEB]
- https://www.npmjs.com/advisories/313[WEB]
- https://www.npmjs.com/package/serialize-to-js#deserialize[WEB]
- http://www.securityfocus.com/bid/96223[WEB]