← Back to CVE List

CVE-2017-5941

Published: 2017-02-09T19:59Z
Last Modified: 2024-11-21T03:28Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE). > MITRE Terms of Use apply – see LICENSE‑MITRE.txt