Executive brief
TeleJSON is a library used to serialize and deserialize JavaScript objects, often used in web applications for cross-frame communication. A security flaw allows an attacker to execute malicious code in a user's browser by sending a specially crafted data payload. This could lead to unauthorized actions, such as stealing session information or manipulating the content of the web page.
Technical details
A DOM-based cross-site scripting (XSS) vulnerability exists in TeleJSON's parse() function due to unsafe deserialization. The library's custom reviver processes a special '_constructor-name_' property and passes its value directly into a 'new Function()' constructor without sanitization to recreate object prototypes. An attacker can exploit this by delivering a malicious JSON payload through vectors like 'postMessage' in cross-frame communication. Successful exploitation allows for arbitrary JavaScript execution in the context of the victim's browser. The issue is fixed in version 6.0.0 by implementing a character allowlist and gating the functionality behind an 'allowFunction' option.
Affected products
- storybookjs telejson < 6.0.0
Timeline
- 2022: patched: Version 6.0.0 released with fix
- 2026-05-20: disclosed: CVE-2026-47099 published