ended4월 3일· 1 sources
TeleJSON Vulnerability Enables Arbitrary JavaScript Execution Through Unsafe JSON Deserialization
TeleJSON의 불안전한 역직렬화 취약점, 임의 코드 실행 노출
Why it matters
TeleJSON's improper validation of the _constructor-name_ property creates a critical attack vector for front-end applications and Storybook instances. Attackers can inject malicious JavaScript code through crafted JSON payloads delivered via cross-frame messaging, potentially compromising user data and application integrity. Immediate upgrade to version 6.0.0 combined with strict origin validation for postMessage listeners is essential to mitigate this risk.
1
Sources
+0
24h
—
Growth
171d
Active
TeleJSONDOM XSSUnsafe deserializationCode executionStorybook