Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.2 npm

Cross-Site Scripting in serialize-javascript

GHSA-h9rv-jmmf-4pgx · CVE-2019-16769

Published · Modified

Description

Versions of serialize-javascript prior to 2.1.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize serialized regular expressions. This vulnerability does not affect Node.js applications.

Recommendation

Upgrade to version 2.1.1 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes