VDB
Sign up
CRITICAL

GHSA-xxvw-45rp-3mj2

Deserialization Code Execution in js-yaml

Quick fix

GHSA-xxvw-45rp-3mj2 — js-yaml: upgrade to the fixed version with the command below.

npm install js-yaml@2.0.5

Details

Versions 2.0.4 and earlier of `js-yaml` are affected by a code execution vulnerability in the YAML deserializer.

## Proof of Concept ``` const yaml = require('js-yaml');

const x = `test: !!js/function > function f() { console.log(1); }();`

yaml.load(x); ```

## Recommendation

Update js-yaml to version 2.0.5 or later, and ensure that all instances where the `.load()` method is called are updated to use `.safeLoad()` instead.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/js-yaml
Introduced in: 0Fixed in: 2.0.5
Fixnpm install js-yaml@2.0.5

References