Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies
serialize-javascript escapes its output so it is safe to embed inside a <script> element. In 7.1.1 that guarantee does not hold for function values: a crafted function body can carry a literal, unescaped </script> into the output, terminating the script element early so the remainder is parsed as HTML. SCRIPT_CLOSE_REGEXP used </script[^>]*> as its first alternative. The character class excludes only >, so a single match could run from one …