VDB
Sign up
HIGH7.3

GHSA-hj76-42vx-jwp4

seroval Affected by Prototype Pollution via JSON Deserialization

Quick fix

GHSA-hj76-42vx-jwp4 — seroval: upgrade to the fixed version with the command below.

npm install seroval@1.4.1

Details

Due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization. This affects only JSON deserialization functionality.

As there is no known workaround, please upgrade to the latest version.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/seroval
Introduced in: 0Fixed in: 1.4.1
Fixnpm install seroval@1.4.1

References