PT-2026-42227 · Telejson · Telejson

Niccolò Parlanti

·

Published

2026-04-02

·

Updated

2026-05-20

·

CVE-2026-47099

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TeleJSON versions prior to 6.0.0
Description An issue exists in the parse() function involving unsafe deserialization. When reconstructing object prototypes, a custom reviver passes the value of the constructor-name property directly to new Function() without sanitization. This allows an attacker to execute arbitrary JavaScript by delivering a crafted JSON payload, for example, through postMessage in cross-frame communication contexts.
Recommendations Update to version 6.0.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-47099
GHSA-CCGF-5RWJ-J3HV

Affected Products

Telejson