{"id":"CVE-2026-104846","title":"Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities","summary":"Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bear…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-843"],"vendor":"lxsmnsyc","product":"seroval","affected":["seroval >= 0.12.0, < 1.6.2"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T16:16:47.363","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104846","references":[{"url":"https://github.com/lxsmnsyc/seroval/commit/f1ffcc96d259f9b5b3d71feb262b58240c90e7b7","label":"security-advisories@github.com"},{"url":"https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-p6vx-979v-rg4c","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T16:22:59.527Z","slug":"CVE-2026-104846","body":"## Overview\n\nSeroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. ECMAScript thenable assimilation then invokes the callable unexpectedly, allowing attacker-controlled JSON to trigger code in applications using plugin-capable Seroval releases. This path bypasses the Promise resolver type-confusion remediation in version 1.5.3 for CVE-2026-59940 because the unexpected invocation occurs through native Promise settlement after the referenced value is deserialized. This issue is fixed in version 1.6.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}