rpm package
opensuse/opencode&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/opencode&distro=openSUSE%20Tumbleweed
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-59940 | Cri | 9.8 | < 1.18.26-1.1 | 1.18.26-1.1 | Aug 18, 2026 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without ve | |
| CVE-2026-23737 | Hig | 7.5 | < 1.18.26-1.1 | 1.18.26-1.1 | Jan 21, 2026 | seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, improper input handling in the JSON deserialization component can lead to arbitrary JavaScript code execution. Exploitation is possible via | |
| CVE-2026-23736 | Hig | 7.3 | < 1.18.26-1.1 | 1.18.26-1.1 | Jan 21, 2026 | seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization. This vulnerability aff |
- affected < 1.18.26-1.1fixed 1.18.26-1.1
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without ve
- affected < 1.18.26-1.1fixed 1.18.26-1.1
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, improper input handling in the JSON deserialization component can lead to arbitrary JavaScript code execution. Exploitation is possible via
- affected < 1.18.26-1.1fixed 1.18.26-1.1
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization. This vulnerability aff