HIGH 7.3 npm

seroval Affected by Prototype Pollution via JSON Deserialization

GHSA-hj76-42vx-jwp4 · CVE-2026-23736

Published · Modified

Description

Due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization.
This affects only JSON deserialization functionality.

As there is no known workaround, please upgrade to the latest version.

Ready to move

Start Securing

Free, no credit card | First findings in minutes