Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. serialize-javascript
  4. ›
  5. CVE-2026-97711

CVE-2026-97711: Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies

September 30, 2026

serialize-javascript escapes its output so it is safe to embed inside a <script> element. In 7.1.1 that guarantee does not hold for function values: a crafted function body can carry a literal, unescaped </script> into the output, terminating the script element early so the remainder is parsed as HTML.

SCRIPT_CLOSE_REGEXP used <\/script[^>]*> as its first alternative. The character class excludes only >, so a single match could run from one </script all the way to the next > anywhere in the source — swallowing a second, complete </script> along the way. Only one replacement is emitted per match, and the plain-code branch neutralizes just the leading < ('< ' + match.slice(1)), so the swallowed tag was re-emitted verbatim.

Reaching that shape requires </script in code position, which is legal JavaScript: x</script=+/ parses as x < /script=+/, a comparison against a regex literal.

const serialize = require('serialize-javascript');
const src = "function f(x){ return x</script=+/ + '</script><img src=x onerror=alert(1)>' }";
const out = serialize({ h: new Function('return ' + src)() });
// {"h":function f(x){ return x< /script=+/ + '</script><img src=x onerror=alert(1)>' }}

Embedded as the README documents (<script>window.S = <%= serialize(state) %></script>) and parsed by Chromium, the script element ends at the injected tag and the <img> becomes a live DOM node with its onerror handler executing in the page origin.

Only the function path is affected. The same payload passed as data is escaped correctly, and options.isJSON / non-function values are unaffected.

References

  • github.com/advisories/GHSA-gfhx-hw2g-v5hg
  • github.com/yahoo/serialize-javascript/commit/2bdbaaff9cb8a4639135eb24cfcd383d3fefb534
  • github.com/yahoo/serialize-javascript/releases/tag/v7.1.2
  • github.com/yahoo/serialize-javascript/security/advisories/GHSA-gfhx-hw2g-v5hg
  • nvd.nist.gov/vuln/detail/CVE-2026-97711

Code Behaviors & Features

Detect and mitigate CVE-2026-97711 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 7.1.1 before 7.1.2

Fixed versions

  • 7.1.2

Solution

Upgrade to version 7.1.2 or above.

Impact 5.4 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Source file

npm/serialize-javascript/CVE-2026-97711.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 01 Oct 2026 00:19:05 +0000.