CVE-2026-97711
### Impact `serialize-javascript` escapes its output so it is safe to embed inside a `<script>` element. In 7.1.1 that guarantee does not hold for **function values**: a crafted function body can carry a literal, unescaped `</script>` into the output, terminating the script element early so the remainder is parsed as HTML. `SCRIPT_CLOSE_REGEXP` used `<\/script[^>]*>` as its first alternative. The character class excludes only `>`, so a single match could run from one `</script` all the way to the next `>` anywhere in the source — swallowing a second, complete `</script>` along the way. Only one replacement is emitted per match, and the plain-code branch neutralizes just the leading `<` (`'< ' + match.slice(1)`), so the swallowed tag was re-emitted verbatim. Reaching that shape requires `</script` in code position, which is legal JavaScript: `x</script=+/` parses as `x < /script=+/`, a comparison against a regex literal. ```js const serialize = require('serialize-javascript'); const src = "function f(x){ return x</script=+/ + '</script><img src=x onerror=alert(1)>' }"; const out = serialize({ h: new Function('return ' + src)() }); // {"h":function f(x){ return x< /script=+/ + '</script><img src=x onerror=alert(1)>' }} ``` Embedded as the README documents (`<script>window.S = <%= serialize(state) %></script>`) and parsed by Chromium, the script element ends at the injected tag and the `<img>` becomes a live DOM node with its `onerror` handler executing in the page origin. Only the function path is affected. The same payload passed as **data** is escaped correctly, and `options.isJSON` / non-function values are unaffected. ### Patches Fixed in **7.1.2**. The wildcard now excludes `<` as well as `>` (`[^<>]*`), so a match can never reach past a second `<`. Every `</script` in the source therefore either begins its own match or is followed by a character the HTML tokenizer does not accept as ending a tag name — it ends the tag name only on TAB, LF, FF, CR, SPACE,
Properties
- ghsa_id
- GHSA-gfhx-hw2g-v5hg
- summary
- Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies
- severity
- low
- last_source
- GitHub Advisory Database
- cve_id
- CVE-2026-97711
- signal_observed_at
- 2026-09-30T23:58:31+00:00
- is_ghsa_only
- false
- retrieved_at
- 2026-09-30T23:58:31+00:00
- ghsa_published
- 2026-09-30T15:40:05Z
- source_url
- https://github.com/advisories/GHSA-gfhx-hw2g-v5hg
- ghsa_updated
- 2026-09-30T15:40:06Z
Related Entities (5)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
Explore deeper with Ninja Signal's threat intelligence graph