CVE-2026-23736
HIGHseroval <1.4.1 - Prototype Pollution
Title source: llmDescription
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization. This vulnerability affects only JSON deserialization functionality. This issue is fixed in version 1.4.1.
Scores
CVSS v3
7.3
EPSS
0.0020
EPSS Percentile
41.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-1321
Status
published
Affected Products (2)
npm/seroval
< 1.4.1npm
lxsmnsyc/seroval
< 1.4.1
Timeline
Published
Jan 21, 2026
Tracked Since
Feb 18, 2026