serialize-javascript is vulnerable to Cross-Site Scripting (XSS)
33
Low Risk
serialize-javascript escapes serialized values so they are safe to embed inside a <script> element, but SCRIPT_CLOSE_REGEXP matches from a bare </script all the way to the next unrelated >, letting one match swallow and re-emit a later, complete </script> tag untouched. A function value containing </script=+/ in code position (legal JavaScript, parsed as a comparison against a regex literal) followed by a string literal such as </script><img src=x onerror=alert(1)> reaches this path, terminating the surrounding script element early so the injected markup runs as live HTML in the page, leading to cross-site scripting. Only function values are affected; string and data values are escaped correctly. The fix excludes < from the regex's character class so a match can no longer span a second </script tag.
You are affected if you are using a version that falls within the vulnerable range and you serialize function values whose source is embedded inside a <script> element.
serialize-javascript is vulnerable to Cross-Site Scripting (XSS) in versions 7.0.1 - 7.1.1.
Upgrade the serialize-javascript library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.