An issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).
{
"extracted_events": [
{
"introduced": "0.5.0"
},
{
"last_affected": "0.5.0"
}
],
"source": "CPE_STRING",
"cpe": "cpe:2.3:a:serialize-to-js_project:serialize-to-js:0.5.0:*:*:*:*:node.js:*:*"
}