serialize-javascript, Cross-site Scripting (XSS), CVE-2026-97711 (Low) -DC-Sep2026-2683

Listen to this Post

serialize-javascript is an npm package that serializes JavaScript values to a superset of JSON, including support for regular expressions and functions. The library provides a function called `serialize()` that converts JavaScript objects into string representations safe for embedding inside `` tag that appears between them.
When a match spans multiple closing tags, only one replacement is emitted per match. The plain-code branch of the replacement logic neutralizes just the leading `<` by prefixing it with a space (‘< ‘ + match.slice(1)), which means any swallowed tag is re-emitted verbatim without escaping. An attacker can exploit this by crafting a function body that contains `x < /script=+/, a comparison against a regex literal.
When the serialized function is embedded inside a `

Scroll to Top