Where
-Infinity
0
Severity
2.3
XSS
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Impact

serialize-javascript escapes its output so it is safe to embed inside a <script> element. In 7.1.1 that guarantee does not hold for function values: a crafted function body can carry a literal, unescaped </script> into the output, terminating the script element early so the remainder is parsed as HTML.

SCRIPTCLOSEREGEXP used <\/script[^>]> as its first alternative. The character class excludes only >, so a single match could run from one </script all the way to the next > anywhere in the source — swallowing a second, complete </script> along the way. Only one replacement is emitted per match, and the plain-code branch neutralizes just the leading < ('< ' + match.slice(1)), so the swallowed tag was re-emitted verbatim.

Reaching that shape requires </script in code position, which is legal JavaScript: x</script=+/ parses as x < /script=+/, a comparison against a regex literal.

js const serialize = require('serialize-javascript'); const src = "function f(x){ return x</script=+/ + '</script><img src=x onerror=alert(1)>' }"; const out = serialize({ h: new Function('return ' + src)() }); // {"h":function f(x){ return x< /script=+/ + '</script><img src=x onerror=alert(1)>' }}

Embedded as the README documents (<script>window.S = <%= serialize(state) %></script>) and parsed by Chromium, the script element ends at the injected tag and the <img> becomes a live DOM node with its onerror handler executing in the page origin.

Only the function path is affected. The same payload passed as data is escaped correctly, and options.isJSON / non-function values are unaffected.

Patches

Fixed in 7.1.2. The wildcard now excludes < as well as > ([^<>]), so a match can never reach past a second <. Every </script in the source therefore either begins its own match or is followed by a character the HTML tokenizer does not accept as ending a tag name — it ends the tag name only on TAB, LF, FF, CR, SPACE, / or >, and emits anything else as text.

Workarounds

Upgrade to 7.1.2. If you cannot upgrade, 7.1.0 and earlier are unaffected, or avoid serializing functions whose source text is attacker-influenced.

Regression note

This is a regression specific to 7.1.1, not a long-standing issue. 7.1.0 and earlier applied the same wildcard but escaped the entire match, so no tag survived. Downstream scanners defaulting to a >= 7.1.0 range would be overly broad.

1 / 2
Source: GitHub
First published (updated )
Severity
4

Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU exhaustion. When serializing a specially crafted "array-like" object (an object that inherits from Array.prototype but has a very large length property), the process enters an intensive loop that consumes 100% CPU and hangs indefinitely. This issue has been patched in version 7.0.5.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203