Skip to content

[pkg-vet-test][do-not-merge] S4 reachable node-serialize@0.0.4 RCE (CVE-2017-5941)#30

Open
Gldywn wants to merge 1 commit into
mainfrom
pkg-vet-test/s4-rce-node-serialize
Open

[pkg-vet-test][do-not-merge] S4 reachable node-serialize@0.0.4 RCE (CVE-2017-5941)#30
Gldywn wants to merge 1 commit into
mainfrom
pkg-vet-test/s4-rce-node-serialize

Conversation

@Gldywn

@Gldywn Gldywn commented May 29, 2026

Copy link
Copy Markdown
Owner

Throwaway fixture: node-serialize@0.0.4 (CVE-2017-5941 deserialization RCE, EPSS ~78pct) as a runtime dependency with its vulnerable unserialize() called from an exported function. High EPSS so it should NOT be auto-ignored. Vulnerable, not malware, no install scripts. DO NOT MERGE.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant