CVE-2017-5941

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
09/02/2017
Last modified:
20/04/2025

Description

An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:node-serialize_project:node-serialize:*:*:*:*:*:node.js:*:* 0.0.4 (including)