A critical vulnerability was found in Seroval, a JavaScript value stringification library. The issue allows for deserialization side effects with plugins enabled, potentially leading to unintended server-side invocation or remote code execution. This vulnerability is fixed in version 1.5.3. The vulnerability affects systems using Seroval versions prior to 1.5.3, especially those with plugins enabled. Deve [truncated]
CVE-2026-23956 is a high-severity vulnerability in Seroval, a JavaScript library for serializing complex values beyond JSON.stringify capabilities. The issue affects versions 0.2.0 through 1.4.0 and was published on January 22, 2026, with a subsequent modification on May 20, 2026. The vulnerability stems from improper handling of user-controlled RegExp serialization, enabling two distinct attack vectors: [truncated]