Intel

AIKIDO-2026-390982

serialize-javascript is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)GHSA-gfhx-hw2g-v5hg Published 4 days ago

33

Low Risk

This Affects:

JSserialize-javascript
7.0.1 - 7.1.1
Fixed in 7.1.2
Are you affected? Scan for Free

TL;DR

serialize-javascript escapes serialized values so they are safe to embed inside a <script> element, but SCRIPT_CLOSE_REGEXP matches from a bare </script all the way to the next unrelated >, letting one match swallow and re-emit a later, complete </script> tag untouched. A function value containing </script=+/ in code position (legal JavaScript, parsed as a comparison against a regex literal) followed by a string literal such as </script><img src=x onerror=alert(1)> reaches this path, terminating the surrounding script element early so the injected markup runs as live HTML in the page, leading to cross-site scripting. Only function values are affected; string and data values are escaped correctly. The fix excludes < from the regex's character class so a match can no longer span a second </script tag.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you serialize function values whose source is embedded inside a <script> element.

Background info

serialize-javascript is vulnerable to Cross-Site Scripting (XSS) in versions 7.0.1 - 7.1.1.

How to fix this

Upgrade the serialize-javascript library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform