Skip to content

fix(deps): update dependency serialize-javascript to ^7.0.7#6159

Open
EhabY wants to merge 1 commit into
mochajs:mainfrom
EhabY:fix-serialize-javascript-vuln
Open

fix(deps): update dependency serialize-javascript to ^7.0.7#6159
EhabY wants to merge 1 commit into
mochajs:mainfrom
EhabY:fix-serialize-javascript-vuln

Conversation

@EhabY

@EhabY EhabY commented Jul 21, 2026

Copy link
Copy Markdown

PR Checklist

Overview

Updates serialize-javascript from ^7.0.2 to ^7.0.7 (latest), which resolves two known vulnerabilities affecting 7.0.2:

  • GHSA-5c6j-r48x-rmvq (high): RCE via RegExp.flags and Date.prototype.toISOString() — affects <= 7.0.2, patched in 7.0.3
  • GHSA-qj8w-gfj5-8c6v / CVE-2026-34043 (medium): CPU exhaustion DoS via crafted array-like objects — affects >= 5.0.0, < 7.0.5, patched in 7.0.5

Updates serialize-javascript past the vulnerable 7.0.2 release
(fixed in 7.0.5).
@EhabY
EhabY force-pushed the fix-serialize-javascript-vuln branch from 669a4f1 to 8a584ef Compare July 21, 2026 12:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant