vulns.co
/
GKData.io MCP

Yahoo serialize-javascript · 2 min read

Serialize JavaScript: every serialized field must retain data semantics

The maintainer describes inconsistent escaping across structured-object serialization: some object-derived strings entered generated JavaScript without equivalent protection. Code execution requires attacker-influenced objects and subsequent executable interpretation of the output. The advisory demonstrates local execution; universal remote exploitability or production compromise is not established.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

The maintainer advisory and official release identify 7.0.3 as the repair. Editorial lesson: audit serialization contracts across every supported type and output consumer, including overridable object behavior. Prefer data-only exchange where possible and avoid granting generated text execution authority merely because a serializer produced it.

Before reading

  • JavaScript object behavior and serialization contracts
  • Data versus executable-output trust boundaries

Context and limits

  • The maintainer table says affected versions are below 7.0.2, but its prose includes 7.0.2. The GitHub-reviewed entry includes 7.0.2; all reviewed sources identify 7.0.3 as patched.
  • The maintainer labels this an incomplete CVE-2020-7660 fix, while the GitHub-reviewed entry assigns no known CVE. The stable identity here is GHSA-5c6j-r48x-rmvq; its 2026 publication does not make the earlier CVE a 2026 identifier.
  • The advisory credits uug4na as reporter; redonkulus is the publishing maintainer. No bounty established.
  • The software-release page displays February 27 without a year in the retrieved rendering. No exact software-release date is inferred; advisory publication is independently explicit.
  • Learning prerequisites and generalized design guidance are editorial. Control of ordinary JSON alone does not establish the object-control and executable-consumer prerequisites.

Sources and provenance

  1. RCE via RegExp.flags and Date.prototype.toISOString() Yahoo serialize-javascript · reviewed 2026-10-03
  2. Serialize JavaScript v7.0.3 release Yahoo serialize-javascript · reviewed 2026-10-03
  3. Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() GitHub Advisory Database · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software