CriticalCritical vulnerability
CVE-2026-104846: Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
GitHub Advisories · officialPublished Oct 5, 2026Risk 50/100
A fulfilled Promise node deserialized by `fromJSON()` can trigger unintended invocation of a plugin-produced callable through native ECMAScript thenable assimilation. This bypasses the type-confusion fix in `[email protected]` (GHSA-mv8w-475r-vwqw / CVE-2026-59940) and affects every plugin-capable release from `0.12.0` through the current `1.6.0`.
Recommended action
Recommended action
Upgrade affected packages to a patched version: seroval 1.6.2.
Technical details
- Vendor
- Not specified
- Product
- seroval
- Exploitation
- none known
- Evidence
- official
CVSS
9.8
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source