Vulnerabilities/

Denial of Service in serialize-to-js

Severity:
High

Description

Versions of serialize-to-js prior to 2.0.0 are vulnerable to Denial of Service. User input is not properly validated, allowing attackers to provide inputs that lead the execution to loop indefinitely.

Recommendation

Update the serialize-to-js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
serialize-to-js
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing