serialize-javascript
npm5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting serialize-javascriptpage 1 of 1
- CVE-2019-16769MEDIUMCVSS 4.2EG 4.2fixed in 2.1.12019-12-05
The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js…
- CVE-2020-7660HIGHCVSS 8.1EG 8.1fixed in 3.1.02020-06-01
serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".
- CVE-2024-11831MEDIUMCVSS 5.4EG 5.4fixed in 6.0.22025-02-10
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malici…
- CVE-2026-34043HIGHCVSS 7.5EG 7.5fixed in 7.0.52026-03-31
Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU exhaustion. When serializing a specially crafted "array-like…
- CVE-2026-97711LOWCVSS 2.3EG 2.3fixed in 7.1.22026-09-29
Serialize JavaScript serializes JavaScript values to a superset of JSON that includes regular expressions and functions. From 7.1.1 until 7.1.2, function values serialized by serialize-javascript are not fully protected against script-clos…
Check whether serialize-javascript is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for serialize-javascript CVEs against the assets you own.
Book a Demo →