Cross-Site Scripting Vulnerability in Serialize-JavaScript Library by Yahoo
CVE-2026-97711

2.3LOW

Key Information:

Vendor

Yahoo

Vendor
CVE Published:
29 September 2026

What is CVE-2026-97711?

The Serialize-JavaScript library from Yahoo has an identified vulnerability where function values serialized from versions 7.1.1 to 7.1.2 may not be fully secured against designated script-closing tags. This security flaw can lead to cross-site scripting (XSS) when serialized functions are executed within script elements, allowing an attacker to manipulate the HTML output and potentially execute malicious scripts. The issue has been rectified in version 7.1.2, making it vital for users of the earlier versions to update promptly to ensure their web applications are secure.

Affected Version(s)

serialize-javascript >= 7.1.1, < 7.1.2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.