HarborGuard / CVE
Back to search
HIGHCVE-2026-23736Published Modified CNA GitHub_M

CVE-2026-23736: seroval Affected by Prototype Pollution via JSON Deserialization

seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization. This vulnerability affects only JSON deserialization functionality. This issue is fixed in version 1.4.1.

Metrics

CVSS v3.1
7.3
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • lxsmnsyc / seroval
    < 1.4.1
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L