Skip to content

fix: patch serialize-javascript vulnerability (GHSA-5c6j-r48x-rmvq)#254

Merged
DCSBL merged 1 commit intomainfrom
fix/serialize-javascript-rce
Mar 24, 2026
Merged

fix: patch serialize-javascript vulnerability (GHSA-5c6j-r48x-rmvq)#254
DCSBL merged 1 commit intomainfrom
fix/serialize-javascript-rce

Conversation

@DCSBL
Copy link
Collaborator

@DCSBL DCSBL commented Mar 24, 2026

Force serialize-javascript to >=7.0.3 via npm overrides to fix RCE vulnerability in versions <=7.0.2 where RegExp.flags and Date.prototype.toISOString() were not properly sanitized.

Force serialize-javascript to >=7.0.3 via npm overrides to fix
RCE vulnerability in versions <=7.0.2 where RegExp.flags and
Date.prototype.toISOString() were not properly sanitized.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@DCSBL DCSBL enabled auto-merge (squash) March 24, 2026 15:47
@DCSBL DCSBL merged commit fb1f67c into main Mar 24, 2026
10 checks passed
@DCSBL DCSBL deleted the fix/serialize-javascript-rce branch March 24, 2026 15:49
@github-actions
Copy link

Visit the preview URL for this PR (updated for commit 9175187):

https://hw-api-documentation--pr254-fix-serialize-javasc-gd3r6n8a.web.app

(expires Tue, 31 Mar 2026 15:49:22 GMT)

🔥 via Firebase Hosting GitHub Action 🌎

Sign: 4accc1c887f1346ec9c563d5645c74c94f610c07

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant