CVE-2026-23736
Due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization.
This affects only JSON deserialization functionality.
As there is no known workaround, please upgrade to the latest version.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-hj76-42vx-jwp4, https://nvd.nist.gov/vuln/detail/CVE-2026-23736, https://github.com/lxsmnsyc/seroval/commit/ce9408ebc87312fcad345a73c172212f2a798060, https://github.com/lxsmnsyc/seroval
