PatchSiren

lxsmnsyc CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL lxsmnsyc CVE published 2026-08-18

CVE-2026-59940

A critical vulnerability was found in Seroval, a JavaScript value stringification library. The issue allows for deserialization side effects with plugins enabled, potentially leading to unintended server-side invocation or remote code execution. This vulnerability is fixed in version 1.5.3. The vulnerability affects systems using Seroval versions prior to 1.5.3, especially those with plugins enabled. Deve [truncated]

HIGH lxsmnsyc CVE published 2026-01-22

CVE-2026-23956

CVE-2026-23956 is a high-severity vulnerability in Seroval, a JavaScript library for serializing complex values beyond JSON.stringify capabilities. The issue affects versions 0.2.0 through 1.4.0 and was published on January 22, 2026, with a subsequent modification on May 20, 2026. The vulnerability stems from improper handling of user-controlled RegExp serialization, enabling two distinct attack vectors: [truncated]