Executive brief
seroval is a JavaScript serialization/deserialization library used for data exchange in web and Node.js applications. A flaw in its JSON deserialization function allows an attacker to inject malicious object keys that pollute the prototype chain, potentially allowing them to modify the behavior of all objects in an application or access sensitive data.
Technical details
The vulnerability is a prototype pollution flaw (CWE-1321) triggered during JSON deserialization due to improper input validation of object keys. An attacker can craft a malicious JSON payload with specially crafted keys to pollute the JavaScript prototype chain. The attack requires no authentication or user interaction and is remotely exploitable over the network. Successful exploitation can lead to data disclosure, data manipulation, or denial of service. The vulnerability affects all versions up to 1.4.0; patched in version 1.4.1 and later.
Affected products
- lxsmnsyc seroval all versions up to and including 1.4.0
Timeline
- 2026-01-21: disclosed
- 2026-01-21: patched: Version 1.4.1 and later contain the fix