CVE-2026-23736

HIGH

seroval <1.4.1 - Prototype Pollution

Title source: llm
STIX 2.1

Description

seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization. This vulnerability affects only JSON deserialization functionality. This issue is fixed in version 1.4.1.

Scores

CVSS v3 7.3
EPSS 0.0021
EPSS Percentile 42.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1321
Status published
Products (2)
lxsmnsyc/seroval < 1.4.1
npm/seroval 0 - 1.4.1npm
Published Jan 21, 2026
Tracked Since Feb 18, 2026