Deserialization of Untrusted Data in Serialize-javascript - #VU128354
Published: April 28, 2026
Serialize-javascript
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data passed via RegExp.flags and Date.prototype.toISOString(). A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Note, the vulnerability exists due to incomplete fix for #VU86835 (CVE-2020-7660).