SCA: security update for serialize-javascript (GHSA-gfhx-hw2g-v5hg)

low Tenable Self-Hosted Container Security Plugin ID 450405

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Serialize JavaScript serializes JavaScript values to a superset of JSON that includes regular expressions
and functions. From 7.1.1 until 7.1.2, function values serialized by serialize-javascript are not fully
protected against script-closing tags in attacker-influenced function source because SCRIPT_CLOSE_REGEXP
can consume a second closing tag inside one match. When the serialized function is embedded in a script
element, the surviving closing tag terminates the element early and causes the remaining output to be
parsed as HTML, enabling cross-site scripting in the page origin. Only function values are affected;
ordinary data values and options.isJSON output are unaffected. This issue is fixed in version 7.1.2.
(CVE-2026-97711)

Solution

Update the serialize-javascript library and its related packages to version 7.1.2 or later.

See Also

https://github.com/advisories/GHSA-gfhx-hw2g-v5hg

Plugin Details

Severity: Low

ID: 450405

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/30/2026

Updated: 9/30/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.44

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2026-97711

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Low

Base Score: 2.3

Threat Score: 0.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/30/2026

Vulnerability Publication Date: 9/29/2026

Reference Information

CVE: CVE-2026-97711