devalue@1.1.1 vulnerabilities

Gets the job done when JSON.stringify can't

Direct Vulnerabilities

Known vulnerabilities in the devalue package. This does not include vulnerabilities belonging to this package’s dependencies.

Cross-site Scripting (XSS)

devalue is a JSON.stringify, but handles cyclical references, repeated references, undefined, regular expressions, dates, Map and Set.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions.

How to fix Cross-site Scripting (XSS)?

Upgrade devalue to version 2.0.1 or higher.