PT-2026-3878 · Seroval · Seroval

Lxsmnsyc

+1

·

Published

2026-01-21

·

Updated

2026-02-27

·

CVE-2026-23736

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions seroval versions 1.4.0 and below
Description seroval provides JavaScript value stringification, handling complex structures beyond the capabilities of JSON.stringify. A flaw in input validation in versions 1.4.0 and below can lead to prototype pollution during JSON deserialization when processing malicious object keys. This issue specifically impacts the JSON deserialization functionality.
Recommendations Update to version 1.4.1 or later.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2026-23736
GHSA-HJ76-42VX-JWP4

Affected Products

Seroval