Sitelet https://github.com/yahoo/serialize-javascript/compare/v7.1.0...v7.1.1
Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: yahoo/serialize-javascript
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v7.1.0
Choose a base ref
...
head repository: yahoo/serialize-javascript
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v7.1.1
Choose a head ref
  • 2 commits
  • 4 files changed
  • 2 contributors

Commits on Aug 29, 2026

  1. fix: fix XSS bypass via split </script payload across function bodies

    The existing escapeFunctionBody() only escaped a complete `</script...>`
    tag when it appeared within a single serialized value, allowing the tag
    to be split across two separately-serialized function bodies to bypass
    the escaping (each half missing either the `</script` prefix or the
    closing `>`).
    
    - SCRIPT_CLOSE_REGEXP now also matches a bare `</script` prefix followed
      by any WHATWG HTML tokenizer delimiter (TAB, LF, FF, CR, SPACE, `/`,
      `>`), so it's escaped even without a closing `>` in the same value.
    - Escaping is lexically aware: string/template/regex literals and
      comments are scanned up front so their contents are still
      unicode-escaped, while `<`/`/` in plain code (comparison operators,
      regex delimiters, division) get a whitespace-insertion instead to
      avoid producing invalid JavaScript syntax.
    - Span classification uses a single forward cursor for O(n) performance
      instead of a per-match linear scan.
    
    Verified against parse5 (real HTML5 tokenizer), eval-based round-trip
    tests for edge cases (String.raw, regex literals with quotes/character
    classes, operator vs. regex-literal ambiguity), and the full test suite
    (93/93 passing).
    
    Refs: #220
    PR-URL: #226
    Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
    okuryu and Copilot authored Aug 29, 2026
    Configuration menu
    Copy the full SHA
    ffda9f1 View commit details
    Browse the repository at this point in the history
  2. release: v7.1.1

    PR-URL: #227
    okuryu authored Aug 29, 2026
    Configuration menu
    Copy the full SHA
    8c8caa7 View commit details
    Browse the repository at this point in the history
Loading