An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).
PoC: scenario-c-block
Thesis scenario test (research only): Scenario C: EPSS-BLOCK path - node-serialize@0.0.4 CVE-2017-5941
PoC: RCE-NodeJs
Exploit Title: Node.JS - 'node-serialize' Remote Code Execution (2), Version: 0.0.4, CVE: CVE-2017-5941
PoC: nodejshell
Exploit de reverseshell para desserialização em NodeJs (CVE-2017-5941)
PoC: Lab-for-cve-2018-15133
Ejecución de exploit de deserialización con CVE-2017-5941
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free