How to use this reference
The maintainer advisory and official release identify 7.0.3 as the repair. Editorial lesson: audit serialization contracts across every supported type and output consumer, including overridable object behavior. Prefer data-only exchange where possible and avoid granting generated text execution authority merely because a serializer produced it.
Before reading
- JavaScript object behavior and serialization contracts
- Data versus executable-output trust boundaries
Context and limits
- The maintainer table says affected versions are below 7.0.2, but its prose includes 7.0.2. The GitHub-reviewed entry includes 7.0.2; all reviewed sources identify 7.0.3 as patched.
- The maintainer labels this an incomplete CVE-2020-7660 fix, while the GitHub-reviewed entry assigns no known CVE. The stable identity here is GHSA-5c6j-r48x-rmvq; its 2026 publication does not make the earlier CVE a 2026 identifier.
- The advisory credits uug4na as reporter; redonkulus is the publishing maintainer. No bounty established.
- The software-release page displays February 27 without a year in the retrieved rendering. No exact software-release date is inferred; advisory publication is independently explicit.
- Learning prerequisites and generalized design guidance are editorial. Control of ordinary JSON alone does not establish the object-control and executable-consumer prerequisites.
Sources and provenance
- RCE via RegExp.flags and Date.prototype.toISOString() Yahoo serialize-javascript · reviewed 2026-10-03
- Serialize JavaScript v7.0.3 release Yahoo serialize-javascript · reviewed 2026-10-03
- Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GitHub Advisory Database · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.