CVE-2026-97711: Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies
Serialize JavaScript serializes JavaScript values to a superset of JSON that includes regular expressions and functions. From 7.1.1 until 7.1.2, function values serialized by serialize-javascript are not fully protected against script-closing tags in attacker-influenced function source because SCRIPTCLOSEREGEXP can consume a second closing tag inside one match. When the serialized function is embedded in a script element, the surviving closing tag terminates the element early and causes the remaining output to be parsed as HTML, enabling cross-site scripting in the page origin. Only function values are affected; ordinary data values and options.isJSON output are unaffected. This issue is fixed in version 7.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
serialize-javascriptto a version that resolves this vulnerability.Fixed in 7.1.2
Event History
Frequently Asked Questions
Which uses are exposed to this issue?
Exposure requires serialize-javascript output containing a function value to be embedded in an HTML script element. Ordinary serialized data values and output generated with options.isJSON are unaffected.
What attacker control is needed for exploitation?
An attacker must be able to influence function source that is passed to serialize-javascript and have the resulting serialization embedded in a script element. A surviving </script> sequence can then close that element early and cause subsequent output to be interpreted as HTML in the page origin.
What should be done if the affected serializer behavior is in use?
Update serialize-javascript to version 7.1.2. Until updating is possible, avoid serializing attacker-influenced function values into script elements; use JSON-only output where compatible, since options.isJSON output is unaffected.