Executive brief
devalue is a JavaScript serialization library used to convert data structures to strings. When serializing multiple promises, an internal promise rejection can remain unhandled even if the application catches the main returned promise, causing Node.js to terminate the process under default behavior. Exploitation is extremely unlikely and the issue is typically introduced by developer timing or error handling patterns rather than malicious input.
Affected products
- npm devalue