/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-11831

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-11831

CGA ID

CGA-72hf-gjp2-m4hx

Severity

5.4

Medium

CVSS V3

Description

A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images