CVE-2026-104846: Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of CVE-2026-59940)
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. ECMAScript thenable assimilation then invokes the callable unexpectedly, allowing attacker-controlled JSON to trigger code in applications using plugin-capable Seroval releases. This path bypasses the Promise resolver type-confusion remediation in version 1.5.3 for CVE-2026-59940 because the unexpected invocation occurs through native Promise settlement after the referenced value is deserialized. This issue is fixed in version 1.6.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
serovalto a version that resolves this vulnerability.Fixed in 1.6.2
Event History
Frequently Asked Questions
Which Seroval versions require remediation?
Versions from 0.12.0 up to, but not including, 1.6.2 are affected. Upgrade to 1.6.2, which fixes this issue.
What conditions are needed for exploitation?
An application must deserialize attacker-controlled JSON with fromJSON in a plugin-capable Seroval release. The exploit path involves a fulfilled Promise control node whose referenced value becomes a plugin-produced thenable carrying a callable.
Does upgrading to 1.5.3 resolve this issue?
No. This issue bypasses the Promise resolver type-confusion remediation introduced in 1.5.3 because invocation occurs during native Promise settlement after the referenced value is deserialized.
What can be done before an upgrade is available?
Do not pass untrusted JSON to fromJSON. In particular, prevent attacker-controlled serialized values from reaching Promise-related deserialization paths in plugin-capable deployments.
How can teams determine whether they are exposed?
Check whether the deployed Seroval version is earlier than 1.6.2 and whether the application uses fromJSON on data that an attacker can control. Exposure also depends on use of a plugin-capable configuration where deserialization can produce the relevant callable-bearing thenable.