VDB
Sign up
HIGH

GHSA-w5q7-3pr9-x44w

Denial of Service in serialize-to-js

Quick fix

GHSA-w5q7-3pr9-x44w — serialize-to-js: upgrade to the fixed version with the command below.

npm install serialize-to-js@2.0.0

Details

Versions of `serialize-to-js` prior to 2.0.0 are vulnerable to Denial of Service. User input is not properly validated, allowing attackers to provide inputs that lead the execution to loop indefinitely.

## Recommendation

Upgrade to version 2.0.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/serialize-to-js
Introduced in: 0Fixed in: 2.0.0
Fixnpm install serialize-to-js@2.0.0

References