Description
Improper input handling in the JSON deserialization component can lead to arbitrary JavaScript code execution.
The vulnerability can be exploited via overriding constant value and error deserialization, which allows indirect access to unsafe JS evaluation.
Recommendation
Update the seroval package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.4.1
- Patched version(s): 1.4.1
References
Could your website be exposed too?
SmartScanner can check your website for seroval Affected by Remote Code Execution via JSON Deserialization and gives you actionable findings to investigate.
Start a free scanRelated Issues
- seroval Affected by Prototype Pollution via JSON Deserialization - CVE-2026-23736
- DbGate: Unauthenticated Remote Code Execution via JSON Script Runner - CVE-2026-47668
- Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE) - CVE-2026-23733
- Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix) - CVE-2026-73649


