HIGH 7.3 npm
seroval Affected by Prototype Pollution via JSON Deserialization
GHSA-hj76-42vx-jwp4 · CVE-2026-23736
Published · Modified
Description
Due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization.
This affects only JSON deserialization functionality.
As there is no known workaround, please upgrade to the latest version.
Ready to move
Start Securing
Free, no credit card | First findings in minutes