Vulnerabilities in serialize-to-js 1.0.0