PatchSiren cyber security CVE debrief
CVE-2017-5941 Node Serialize Project CVE debrief
CVE-2017-5941 is a critical deserialization vulnerability in node-serialize 0.0.4 for Node.js. According to the CVE description and NVD record, untrusted data passed to unserialize() can be abused to achieve arbitrary code execution, which aligns with CWE-502 (deserialization of untrusted data). The NVD CVSS vector rates this as network-exploitable with no privileges or user interaction required and high impact to confidentiality, integrity, and availability.
- Vendor
- Node Serialize Project
- Product
- Node-Serialize
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-09
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-09
- Advisory updated
- 2026-05-13
Who should care
Teams running Node.js applications that use node-serialize 0.0.4, especially any service that accepts serialized data from users, partners, queues, APIs, or other untrusted sources and passes it into unserialize().
Technical summary
The vulnerable package is node-serialize_project:node-serialize up to and including version 0.0.4. NVD classifies the issue as CWE-502 and assigns CVSS 3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8). The core risk is unsafe deserialization: attacker-controlled input reaching unserialize() may trigger code execution through crafted JavaScript object content, including the IIFE pattern described in the CVE record.
Defensive priority
Immediate. This is a critical, remotely exploitable deserialization flaw with full impact potential if untrusted data can reach the vulnerable function.
Recommended defensive actions
- Identify all uses of node-serialize and confirm whether version 0.0.4 or earlier is deployed.
- Stop passing untrusted or externally influenced data into unserialize(); treat this API as unsafe for attacker-controlled input.
- Upgrade or replace node-serialize with a safer serialization approach that does not execute code during parsing.
- Add input provenance checks and validate that only trusted, tightly controlled data reaches any deserialization logic.
- Review logs and application code paths that may expose serialized blobs through APIs, message queues, or storage restores.
- If immediate upgrade is not possible, isolate affected services and restrict exposure of any endpoint that processes serialized input.
Evidence notes
The vulnerability details come from the supplied CVE description and NVD metadata. Official record links confirm the CVE entry and affected package/version range, while the NVD reference data lists CWE-502 and the high-severity CVSS 3.1 vector. Third-party references in the corpus include advisories and exploit writeups, but this debrief does not rely on their contents beyond their existence in the record.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5941 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5941
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5941 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5941
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://nodesecurity.io/advisories/311
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://opsecx.com/index.php/2017/02/08/exploiting-node-js-deserialization-bug-for-remote-code-execution/
[email protected] - Exploit, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.