NodeJS/serialize-javascript/6.0.1


Serialize JavaScript to a superset of JSON that includes regular expressions and functions.

https://www.npmjs.com/package/serialize-javascript
BSD-3-Clause

1 Security Vulnerabilities

Cross-site Scripting (XSS) in serialize-javascript

Published date: 2025-02-10T18:30:47Z
CVE: CVE-2024-11831
Links:

A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.

Affected versions: ["6.0.0", "6.0.1"]
Secure versions: [3.1.0, 4.0.0, 5.0.0, 5.0.1, 6.0.2]
Recommendation: Update to version 6.0.2.

24 Other Versions

Version License Security Released
6.0.2 BSD-3-Clause 2024-01-09 - 01:06 over 1 year
6.0.1 BSD-3-Clause 1 2023-01-15 - 14:34 over 2 years
6.0.0 BSD-3-Clause 1 2021-06-21 - 14:01 about 4 years
5.0.1 BSD-3-Clause 2020-09-10 - 12:53 almost 5 years
5.0.0 BSD-3-Clause 2020-09-09 - 12:32 almost 5 years
4.0.0 BSD-3-Clause 2020-06-08 - 13:40 about 5 years
3.1.0 BSD-3-Clause 2020-05-28 - 11:37 about 5 years
3.0.0 BSD-3-Clause 1 2020-02-16 - 13:39 over 5 years
2.1.2 BSD-3-Clause 1 2019-12-09 - 09:19 over 5 years
2.1.1 BSD-3-Clause 1 2019-12-05 - 09:40 over 5 years
2.1.0 BSD-3-Clause 2 2019-09-04 - 12:33 almost 6 years
2.0.0 BSD-3-Clause 2 2019-09-04 - 12:09 almost 6 years
1.9.1 BSD-3-Clause 2 2019-09-04 - 12:07 almost 6 years
1.9.0 BSD-3-Clause 2 2019-08-29 - 12:37 almost 6 years
1.8.0 BSD-3-Clause 2 2019-08-20 - 12:51 almost 6 years
1.7.0 BSD-3-Clause 2 2019-04-16 - 12:19 about 6 years
1.6.1 BSD-3-Clause 2 2018-12-28 - 07:34 over 6 years
1.6.0 BSD-3-Clause 2 2018-12-24 - 14:33 over 6 years
1.5.0 BSD-3-Clause 2 2018-04-18 - 00:08 about 7 years
1.4.0 BSD-3-Clause 2 2017-07-15 - 12:46 almost 8 years
1.3.0 BSD-3-Clause 2 2016-05-31 - 21:52 about 9 years
1.2.0 BSD-3-Clause 2 2016-02-29 - 23:35 over 9 years
1.1.2 BSD-3-Clause 2 2015-09-09 - 16:59 almost 10 years
1.0.0 BSD 2 2014-09-16 - 16:06 almost 11 years