VDB
Sign up
CRITICAL9.8

GHSA-mm62-wxc8-cf7m

Code Execution Through IIFE in serialize-to-js

Quick fix

GHSA-mm62-wxc8-cf7m — serialize-to-js: upgrade to the fixed version with the command below.

npm install serialize-to-js@1.0.0

Details

Affected versions of `serialize-to-js` may be vulnerable to arbitrary code execution through an Immediately Invoked Function Expression (IIFE).

## Proof of Concept ```js var payload = "{e: (function(){ eval('console.log(`exploited`)') })() }" var serialize = require('serialize-to-js'); serialize.deserialize(payload); ```

## Recommendation

Update to version 1.0.0, or later, and review [this disclaimer](https://www.npmjs.com/package/serialize-to-js#deserialize) from the author.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/serialize-to-js
Introduced in: 0Fixed in: 1.0.0
Fixnpm install serialize-to-js@1.0.0

References