Description
Due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization. This affects only JSON deserialization functionality.
As there is no known workaround, please upgrade to the latest version.
Recommendation
Update the seroval package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.4.1
- Patched version(s): 1.4.1
References
Could your website be exposed too?
SmartScanner can check your website for seroval Affected by Prototype Pollution via JSON Deserialization and gives you actionable findings to investigate.
Start a free scanRelated Issues
- seroval Affected by Remote Code Execution via JSON Deserialization - CVE-2026-23737
- Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__ - CVE-2026-54335
- Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` - CVE-2026-42044
- form-data-objectizer: Prototype pollution in form-data-objectizer via bracket-notation form keys - CVE-2026-46510


