Description
telejson versions prior to 6.0.0 (released 2022) are vulnerable to DOM-based Cross-Site Scripting (XSS) through unsafe deserialisation. Attacker-controlled input from the _constructor-name_ property in parsed JSON is passed directly to new Function() without sanitisation, allowing arbitrary JavaScript execution.
Recommendation
Update the telejson package to the latest compatible version. Followings are version details:
- Affected version(s): < 6.0.0
- Patched version(s): 6.0.0
References
Could your website be exposed too?
SmartScanner can check your website for TeleJSON: DOM XSS via unsanitised constructor name in `new Function()` and gives you actionable findings to investigate.
Start a free scanRelated Issues
- CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function - CVE-2026-26861
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes - CVE-2026-41692
- Unhead has XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check - CVE-2026-31860


