Description
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. ECMAScript thenable assimilation then invokes the callable unexpectedly, allowing attacker-controlled JSON to trigger code in applications using plugin-capable Seroval releases. This path bypasses the Promise resolver type-confusion remediation in version 1.5.3 for CVE-2026-59940 because the unexpected invocation occurs through native Promise settlement after the referenced value is deserialized. This issue is fixed in version 1.6.2.
Published: 2026-10-02
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution via untrusted thenable invocation
Action: Patch Now
AI Analysis

Impact

Seroval’s fromJSON routine, when processing fulfilled Promise control nodes, can pass a plugin‑produced callable‑bearing thenable to a native Promise resolver. The ECMAScript thenable assimilation process then calls that attacker‑controlled function unexpectedly, enabling arbitrary code execution in the host application. This type‑confusion issue is classified as CWE‑843, data type mismatch, and it allows a malicious party to execute code without additional privileges as the affected application’s runtime will invoke the callable.

Affected Systems

The vulnerability exists in lxsmnsyc’s Seroval library from version 0.12.0 up through 1.6.2. Any application that incorporates these releases and accepts external JSON data via fromJSON is affected. The fix was introduced in version 1.6.2, so newer releases are safe.

Risk and Exploitability

With a CVSS score of 9.8 the flaw carries critical severity. An attacker can deliver malicious JSON through any interface that the application trusts (HTTP payloads, file imports, etc.). The deserialization path does not perform type validation on the Promise thenable, so the attacker’s callable is invoked as part of native Promise settlement. Because this effect occurs automatically during normal Promise resolution, exploitation requires no additional steps beyond supplying the crafted JSON, making this risk both high and readily exploitable.

Generated by OpenCVE AI on October 2, 2026 at 17:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Seroval to version 1.6.2 or later to remove the vulnerable thenable handling.
  • If upgrade is not yet possible, eliminate or tightly restrict plugin usage in Seroval so that no external callables can be injected through thenables.
  • Sanitize or reject untrusted JSON input before passing it to fromJSON, ensuring that only internally generated data is deserialized.

Generated by OpenCVE AI on October 2, 2026 at 17:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Lxsmnsyc
Lxsmnsyc seroval
Vendors & Products Lxsmnsyc
Lxsmnsyc seroval

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. ECMAScript thenable assimilation then invokes the callable unexpectedly, allowing attacker-controlled JSON to trigger code in applications using plugin-capable Seroval releases. This path bypasses the Promise resolver type-confusion remediation in version 1.5.3 for CVE-2026-59940 because the unexpected invocation occurs through native Promise settlement after the referenced value is deserialized. This issue is fixed in version 1.6.2.
Title Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of CVE-2026-59940)
Weaknesses CWE-843
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Lxsmnsyc Seroval
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-02T15:59:45.802Z

Reserved: 2026-10-02T14:38:43.243Z

Link: CVE-2026-104846

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:47.230

Modified: 2026-10-02T16:16:47.363

Link: CVE-2026-104846

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T18:00:04Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')