CVE-2026-104846: CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') in lxsmnsyc seroval
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. ECMAScript thenable assimilation then invokes the callable unexpectedly, allowing attacker-controlled JSON to trigger code in applications using plugin-capable Seroval releases. This path bypasses the Promise resolver type-confusion remediation in version 1.5.3 for CVE-2026-59940 because the unexpected invocation occurs through native Promise settlement after the referenced value is deserialized. This issue is fixed in version 1.6.2.
AI Analysis
Technical Summary
Seroval is a library that facilitates JavaScript value stringification, including complex structures beyond JSON.stringify. Versions from 0.12.0 up to but not including 1.6.2 contain a vulnerability in the fromJSON deserialization process where a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. The ECMAScript thenable assimilation mechanism then invokes this callable unexpectedly, enabling attacker-controlled JSON to execute code in applications using plugin-capable Seroval releases. This vulnerability bypasses the type-confusion remediation introduced in version 1.5.3 for a related CVE (CVE-2026-59940) because the invocation occurs through native Promise settlement after deserialization. The issue is resolved in Seroval version 1.6.2.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary code in applications using vulnerable Seroval versions by crafting malicious JSON input that triggers unexpected callable invocation during Promise resolution. The CVSS v3.1 score is 9.8 (critical), reflecting network attack vector, low complexity, no privileges or user interaction required, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade Seroval to version 1.6.2 or later, where this vulnerability is fixed. No other mitigations are indicated. Patch status is confirmed fixed in 1.6.2.
CVE-2026-104846: CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') in lxsmnsyc seroval
Description
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. ECMAScript thenable assimilation then invokes the callable unexpectedly, allowing attacker-controlled JSON to trigger code in applications using plugin-capable Seroval releases. This path bypasses the Promise resolver type-confusion remediation in version 1.5.3 for CVE-2026-59940 because the unexpected invocation occurs through native Promise settlement after the referenced value is deserialized. This issue is fixed in version 1.6.2.
CVSS v3.1
Score 9.8critical
Affected software
lxsmnsyc
seroval
pkg:github/lxsmnsyc/serovalRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Seroval is a library that facilitates JavaScript value stringification, including complex structures beyond JSON.stringify. Versions from 0.12.0 up to but not including 1.6.2 contain a vulnerability in the fromJSON deserialization process where a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. The ECMAScript thenable assimilation mechanism then invokes this callable unexpectedly, enabling attacker-controlled JSON to execute code in applications using plugin-capable Seroval releases. This vulnerability bypasses the type-confusion remediation introduced in version 1.5.3 for a related CVE (CVE-2026-59940) because the invocation occurs through native Promise settlement after deserialization. The issue is resolved in Seroval version 1.6.2.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary code in applications using vulnerable Seroval versions by crafting malicious JSON input that triggers unexpected callable invocation during Promise resolution. The CVSS v3.1 score is 9.8 (critical), reflecting network attack vector, low complexity, no privileges or user interaction required, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade Seroval to version 1.6.2 or later, where this vulnerability is fixed. No other mitigations are indicated. Patch status is confirmed fixed in 1.6.2.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-02T14:38:43.243Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abfd8f5a43b0b3b89d5a0ee
Added to database: 10/02/2026, 16:16:53 UTC
Last enriched: 10/02/2026, 16:31:06 UTC
Last updated: 10/02/2026, 18:39:52 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.