CVE-2017-5941
CRITICAL 9.8EPSS 61.0%
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 61.02% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2017-02-09
- Updated
- 2024-08-05
Proof-of-concept exploits (9)
- http://packetstormsecurity.com/files/161356/Node.JS-Remote-Code-Execution.html
- Frivolous-scholar/CVE-2017-5941-NodeJS-RCE0★ · 2020-05-12
- arthurvmbl/nodejshell2★ · 2023-08-27
- gitaalekhyapaul/vuln-app9★ · 2021-06-13
- kylew1004/cve-2017-5941-poc-docker-lab0★ · 2025-08-10
- rodolfomarianocy/nodeserial3★ · 2024-06-02
- turnernator1/Node.js-CVE-2017-59410★ · 2026-02-16
- uartu0/nodejshell2★ · 2023-08-27
- f41k0n/RCE-NodeJs
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/50036
- https://www.exploit-db.com/exploits/49552
- https://www.exploit-db.com/exploits/45265