Impact
Seroval’s fromJSON routine, when processing fulfilled Promise control nodes, can pass a plugin‑produced callable‑bearing thenable to a native Promise resolver. The ECMAScript thenable assimilation process then calls that attacker‑controlled function unexpectedly, enabling arbitrary code execution in the host application. This type‑confusion issue is classified as CWE‑843, data type mismatch, and it allows a malicious party to execute code without additional privileges as the affected application’s runtime will invoke the callable.
Affected Systems
The vulnerability exists in lxsmnsyc’s Seroval library from version 0.12.0 up through 1.6.2. Any application that incorporates these releases and accepts external JSON data via fromJSON is affected. The fix was introduced in version 1.6.2, so newer releases are safe.
Risk and Exploitability
With a CVSS score of 9.8 the flaw carries critical severity. An attacker can deliver malicious JSON through any interface that the application trusts (HTTP payloads, file imports, etc.). The deserialization path does not perform type validation on the Promise thenable, so the attacker’s callable is invoked as part of native Promise settlement. Because this effect occurs automatically during normal Promise resolution, exploitation requires no additional steps beyond supplying the crafted JSON, making this risk both high and readily exploitable.
OpenCVE Enrichment