CVE-2026-104846: Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of CVE-2026-59940)

Published Oct 2, 2026
·
Updated

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. ECMAScript thenable assimilation then invokes the callable unexpectedly, allowing attacker-controlled JSON to trigger code in applications using plugin-capable Seroval releases. This path bypasses the Promise resolver type-confusion remediation in version 1.5.3 for CVE-2026-59940 because the unexpected invocation occurs through native Promise settlement after the referenced value is deserialized. This issue is fixed in version 1.6.2.

Affected Software

1 affected component
npm/seroval>=0.12.0<1.6.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade seroval to a version that resolves this vulnerability.

    Fixed in 1.6.2

Event History

Oct 2, 2026
CVE Published
via MITRE·03:59 PM
Data Sourced
via MITRE·03:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which Seroval versions require remediation?

Versions from 0.12.0 up to, but not including, 1.6.2 are affected. Upgrade to 1.6.2, which fixes this issue.

2

What conditions are needed for exploitation?

An application must deserialize attacker-controlled JSON with fromJSON in a plugin-capable Seroval release. The exploit path involves a fulfilled Promise control node whose referenced value becomes a plugin-produced thenable carrying a callable.

3

Does upgrading to 1.5.3 resolve this issue?

No. This issue bypasses the Promise resolver type-confusion remediation introduced in 1.5.3 because invocation occurs during native Promise settlement after the referenced value is deserialized.

4

What can be done before an upgrade is available?

Do not pass untrusted JSON to fromJSON. In particular, prevent attacker-controlled serialized values from reaching Promise-related deserialization paths in plugin-capable deployments.

5

How can teams determine whether they are exposed?

Check whether the deployed Seroval version is earlier than 1.6.2 and whether the application uses fromJSON on data that an attacker can control. Exposure also depends on use of a plugin-capable configuration where deserialization can produce the relevant callable-bearing thenable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203