Cross-Site Scripting Vulnerability in Serialize-JavaScript Library by Yahoo
CVE-2026-97711
2.3LOW
What is CVE-2026-97711?
The Serialize-JavaScript library from Yahoo has an identified vulnerability where function values serialized from versions 7.1.1 to 7.1.2 may not be fully secured against designated script-closing tags. This security flaw can lead to cross-site scripting (XSS) when serialized functions are executed within script elements, allowing an attacker to manipulate the HTML output and potentially execute malicious scripts. The issue has been rectified in version 7.1.2, making it vital for users of the earlier versions to update promptly to ensure their web applications are secure.
Affected Version(s)
serialize-javascript >= 7.1.1, < 7.1.2
