GHSA-ccgf-5rwj-j3hv
## Summary telejson versions prior to 6.0.0 (released 2022) are vulnerable to DOM-based Cross-Site Scripting (XSS) through unsafe deserialisation. Attacker-controlled input from the `_constructor-name_` property in parsed JSON is passed directly to `new Function()` without sanitisation, allowing arbitrary JavaScript execution. ## Affected versions | Package | Affected | Fixed | |----------|-----------|----------| | telejson | < 6.0.0 | >= 6.0.0 | ## Details telejson's `parse()` function uses a custom reviver to reconstruct JavaScript objects from serialised JSON. When processing objects with a `_constructor-name_` property, the reviver passes the constructor name directly to `new Function()` to recreate the object's prototype. In versions prior to 6.0.0, this constructor name is not sanitised. An attacker who can deliver a crafted JSON payload to `telejson.parse()` (for example, via `postMessage` in applications that use telejson for cross-frame communication) can inject arbitrary JavaScript into the `new Function()` call. **Vulnerable code** ([`src/index.ts`, lines 293-299 at v5.3.3](https://github.com/storybookjs/telejson/blob/v5.3.3/src/index.ts#L293-L299)): ```ts if (isObject<ValueContainer>(value) && value['_constructor-name_']) { const name = value['_constructor-name_']; if (name !== 'Object') { const Fn = new Function(`return function ${name}(){}`)(); Object.setPrototypeOf(value, new Fn()); } ``` **Fixed code** ([`src/index.ts`, lines 340-346 at v6.0.0](https://github.com/storybookjs/telejson/blob/v6.0.0/src/index.ts#L340-L346)): ```ts if (isObject<ValueContainer>(value) && value['_constructor-name_'] && options.allowFunction) { const name = value['_constructor-name_']; if (name !== 'Object') { const Fn = new Function(`return function ${name.replace(/[\W_]+/g, '')}(){}`)(); Object.setPrototypeOf(value, new Fn()); } ``` The fix introduces two mitigations: a character allowlist via regex that strips non
Properties
- ghsa_id
- GHSA-ccgf-5rwj-j3hv
- summary
- TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`
- severity
- low
- cve_id
- GHSA-ccgf-5rwj-j3hv
- is_ghsa_only
- true
- ghsa_published
- 2026-04-02T23:21:23Z
- source_url
- https://github.com/advisories/GHSA-ccgf-5rwj-j3hv
- ghsa_updated
- 2026-04-02T23:21:26Z
Related Entities (3)
HAS_WEAKNESS (1)
REPORTED_BY (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph