Skip to content

chore: update dependency serialize-javascript to v7.1.2 [security] - #7731

Merged
pditommaso merged 1 commit into
masterfrom
renovate/npm-serialize-javascript-vulnerability
Oct 1, 2026
Merged

pditommaso merged 1 commit into
masterfrom
renovate/npm-serialize-javascript-vulnerability

Conversation

@seqeralabs-renovate

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
serialize-javascript overrides patch 7.1.1 → 7.1.2

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies

CVE-2026-97711 / GHSA-gfhx-hw2g-v5hg

More information

Details

Impact

serialize-javascript escapes its output so it is safe to embed inside a
<script> element. In 7.1.1 that guarantee does not hold for function
values
: a crafted function body can carry a literal, unescaped </script>
into the output, terminating the script element early so the remainder is
parsed as HTML.

SCRIPT_CLOSE_REGEXP used <\/script[^>]*> as its first alternative. The
character class excludes only >, so a single match could run from one
</script all the way to the next > anywhere in the source — swallowing a
second, complete </script> along the way. Only one replacement is emitted
per match, and the plain-code branch neutralizes just the leading <
('< ' + match.slice(1)), so the swallowed tag was re-emitted verbatim.

Reaching that shape requires </script in code position, which is legal
JavaScript: x</script=+/ parses as x < /script=+/, a comparison against a
regex literal.

const serialize = require('serialize-javascript');
const src = "function f(x){ return x</script=+/ + '</script><img src=x onerror=alert(1)>' }";
const out = serialize({ h: new Function('return ' + src)() });
// {"h":function f(x){ return x< /script=+/ + '</script><img src=x onerror=alert(1)>' }}

Embedded as the README documents (<script>window.S = <%= serialize(state) %></script>)
and parsed by Chromium, the script element ends at the injected tag and the
<img> becomes a live DOM node with its onerror handler executing in the
page origin.

Only the function path is affected. The same payload passed as data is
escaped correctly, and options.isJSON / non-function values are unaffected.

Patches

Fixed in 7.1.2. The wildcard now excludes < as well as >
([^<>]*), so a match can never reach past a second <. Every </script
in the source therefore either begins its own match or is followed by a
character the HTML tokenizer does not accept as ending a tag name — it ends
the tag name only on TAB, LF, FF, CR, SPACE, / or >, and emits anything
else as text.

Workarounds

Upgrade to 7.1.2. If you cannot upgrade, 7.1.0 and earlier are
unaffected, or avoid serializing functions whose source text is
attacker-influenced.

Regression note

This is a regression specific to 7.1.1, not a long-standing issue. 7.1.0 and
earlier applied the same wildcard but escaped the entire match, so no tag
survived. Downstream scanners defaulting to a >= 7.1.0 range would be
overly broad.

Severity

  • CVSS Score: 2.3 / 10 (Low)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

yahoo/serialize-javascript (serialize-javascript)

v7.1.2

Compare Source

See: GHSA-gfhx-hw2g-v5hg


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@netlify

netlify Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for nextflow-docs ready!

Name Link
🔨 Latest commit 638ba95
🔍 Latest deploy log https://app.netlify.com/projects/nextflow-docs/deploys/6abde58e252aae0008e480cb
😎 Deploy Preview https://deploy-preview-7731--nextflow-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@pditommaso
pditommaso merged commit 0c4e081 into master Oct 1, 2026
26 checks passed
@pditommaso
pditommaso deleted the renovate/npm-serialize-javascript-vulnerability branch October 1, 2026 13:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant