VYPR

seroval

by Seroval

CVEs (1)

  • CVE-2026-59940criJul 24, 2026
    risk 0.59cvss epss

    ## Summary A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input to cause Promise control nodes to operate on values from the general deserialization reference table without first verifying that those values were genuine internal promise resolver…