Intel

AIKIDO-2024-10066

serialize-javascript is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 30, 2024

64

Medium Risk

This Affects:

JSserialize-javascript
6.0.0 - 6.0.1
Fixed in 6.0.2
Are you affected? Scan for Free

TL;DR

Affected versions of the serialize-javascript library are vulnerable to Cross-site Scripting (XSS) due to unsanitized URLs. Attackers can inject unsafe HTML characters through non-HTTP URLs in the serialize function.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

serialize-javascript is vulnerable to Cross-site Scripting (XSS) in versions 6.0.0 - 6.0.1.

How to fix this

Upgrade the serialize-javascript library to the patch version.