GHSA-p6vx-979v-rg4c: Critical severity npm/seroval vulnerability
A fulfilled Promise node deserialized by fromJSON() can trigger unintended invocation of a plugin-produced callable through native ECMAScript thenable assimilation. This bypasses the type-confusion fix in seroval@1.5.3 (GHSA-mv8w-475r-vwqw / CVE-2026-59940) and affects every plugin-capable release from 0.12.0 through the current 1.6.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/serovalto a version that resolves this vulnerability.Fixed in 1.6.2
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using plugin-capable seroval releases from 0.12.0 through 1.6.0 are affected. The issue is remotely exploitable without privileges or user interaction according to the supplied CVSS vector.
What input is required to trigger the issue?
An attacker needs a fulfilled Promise node that is processed by fromJSON(). During deserialization, native ECMAScript thenable assimilation can invoke a callable produced by a plugin.
Does upgrading to seroval 1.5.3 resolve this issue?
No. The issue bypasses the type-confusion fix introduced in seroval 1.5.3, and the affected range includes the current 1.6.0 release.