CVE-2017-5954: Serialize-To-Js Project Serialize-To-Js

Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.

An issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).

Affected products

Published 2017-02-10. Last modified 2026-06-17.