Code Execution through IIFE in node-serialize
Critical severity
GitHub Reviewed
Published
Jul 18, 2018
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Feb 9, 2017
Published to the GitHub Advisory Database
Jul 18, 2018
Reviewed
Jun 16, 2020
Last updated
Feb 1, 2023
Affected versions of
node-serialize
can be abused to execute arbitrary code via an immediately invoked function expression (IIFE) if untrusted user input is passed intounserialize()
.Recommendation
There is no direct patch for this issue. The package author has reviewed this advisory, and provided the following recommendation:
References