Vendorsserialize-to-js Projectserialize-to-js0.5.0
Vulnerabilities

serialize-to-js Project serialize-to-js 0.5.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2017-5954
An issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).
Published 2017-02-10 · Modified
9.8EPSS 0.045