VYPR

seroval

by Seroval

CVEs (1)

  • CVE-2026-59940CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without…