Vulnerability library
Security checkJune 08, 2026

TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Low severitynpmtelejson

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

telejson versions prior to 6.0.0 (released 2022) are vulnerable to DOM-based Cross-Site Scripting (XSS) through unsafe deserialisation. Attacker-controlled input from the _constructor-name_ property in parsed JSON is passed directly to new Function() without sanitisation, allowing arbitrary JavaScript execution.

Recommendation

Update the telejson package to the latest compatible version. Followings are version details:

  • Affected version(s): < 6.0.0
  • Patched version(s): 6.0.0

References

Could your website be exposed too?

SmartScanner can check your website for TeleJSON: DOM XSS via unsanitised constructor name in `new Function()` and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated June 08, 2026