Vulnerabilities in serialize-to-js 0.1.2