CVE-2026-104846
Deferred Deferred - Pending Action

Seroval Promise Resolver Type Confusion via Plugin Callable

Vulnerability report for CVE-2026-104846, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. ECMAScript thenable assimilation then invokes the callable unexpectedly, allowing attacker-controlled JSON to trigger code in applications using plugin-capable Seroval releases. This path bypasses the Promise resolver type-confusion remediation in version 1.5.3 for CVE-2026-59940 because the unexpected invocation occurs through native Promise settlement after the referenced value is deserialized. This issue is fixed in version 1.6.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
seroval seroval From 0.12.0 (inc) to 1.6.2 (inc)
seroval seroval 1.6.2
lxsmnsyc seroval From 0.12.0 (inc) to 1.6.1 (exc)
lxsmnsyc seroval 1.6.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-843 The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the seroval library versions 0.12.0 to 1.6.2. It involves improper handling of thenable objects during deserialization, allowing attacker-controlled JSON to trigger code execution. The issue bypasses a previous fix for type confusion and enables prototype pollution or unexpected code execution through native Promise settlement.

Detection Guidance

To detect this vulnerability, check if your system uses seroval versions between 0.12.0 and 1.6.0. Run: npm list seroval or grep "seroval" package.json. If the version is within this range, the system is vulnerable.

Impact Analysis

The vulnerability allows remote attackers to execute arbitrary code without user interaction or privileges. Applications using vulnerable seroval versions may be compromised, leading to data breaches, system manipulation, or denial of service. The attack can occur through crafted JSON input processed by the fromJSON function.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality requirements and HIPAA's safeguards for protected health information. Non-compliance risks include legal penalties, reputational damage, and loss of trust due to potential data breaches.

Mitigation Strategies

Immediately update seroval to version 1.6.2 or later. Use: npm update seroval or npm install seroval@latest. Verify the update with npm list seroval.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104846. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart