CVE Explorer
CVE-2026-23737
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, improper input handling in the JSON deserialization component can lead to arbitrary JavaScript code execution. Exploitation is possible via overriding constant value and error deserialization, allowing indirect access to unsafe JS evaluation. At minimum, attackers need the ability to perform 4 separate requests on the same function, and partial knowledge of
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"seroval","vendor":"lxsmnsyc","versions":[{"status":"affected","version":"< 1.4.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:36570704aa92a56b59275e9cdde13e6f5b2a752080bfa94db171d50e80e701b6 · sha256:5b84f642f3f9d755… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:36570704aa92a56b59275e9cdde13e6f5b2a752080bfa94db171d50e80e701b6 · sha256:5b84f642f3f9d755… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-502","description":"CWE-502: Deserialization of Untrusted Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:36570704aa92a56b59275e9cdde13e6f5b2a752080bfa94db171d50e80e701b6 · sha256:5b84f642f3f9d755… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/lxsmnsyc/seroval/commit/ce9408ebc87312fcad345a73c172212f2a798060","tags":["x_refsource_MISC"],"url":"https://github.com/lxsmnsyc/seroval/commit/ce9408ebc87312fcad345a73c172212f2a798060"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:36570704aa92a56b59275e9cdde13e6f5b2a752080bfa94db171d50e80e701b6 · sha256:5b84f642f3f9d755… · /containers/cna/references/1
{"name":"https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-3rxj-6cgf-8cfw","tags":["x_refsource_CONFIRM"],"url":"https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-3rxj-6cgf-8cfw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:36570704aa92a56b59275e9cdde13e6f5b2a752080bfa94db171d50e80e701b6 · sha256:5b84f642f3f9d755… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.