Launch Week Day 1: Announcing Security Design Review
LOW 3.1 npm

Cross-Site Scripting in serialize-to-js

GHSA-3fjq-93xj-3f3f · CVE-2019-16772

Published · Modified

Description

Versions of serialize-to-js prior to 3.0.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize serialized regular expressions. This vulnerability does not affect Node.js applications.

Recommendation

Upgrade to version 3.0.1 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes