Prototype Pollution Vulnerability in seroval by lxsmnsyc
CVE-2026-23736

7.3HIGH

Key Information:

Vendor

Lxsmnsyc

Status
Vendor
CVE Published:
21 January 2026

What is CVE-2026-23736?

The seroval library, which enhances JavaScript value stringification, contains a vulnerability in its JSON deserialization functionality. This issue arises from improper input validation in versions up to 1.4.0, allowing an attacker to create a malicious object key that can exploit prototype pollution. The vulnerability has been addressed in version 1.4.1, making it essential for users to update their installations to protect against potential security risks.

Affected Version(s)

seroval < 1.4.1

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.