GHSA-p6vx-979v-rg4cCriticalCVSS 9.8

Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)

Published
October 5, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (1)

📋 Description

A fulfilled Promise node deserialized by fromJSON() can trigger unintended invocation of a plugin-produced callable through native ECMAScript thenable assimilation. This bypasses the type-confusion fix in [email protected] (GHSA-mv8w-475r-vwqw / CVE-2026-59940) and affects every plugin-capable release from 0.12.0 through the current 1.6.0.

🎯 Affected products1

  • npm/seroval:>= 0.12.0, <= 1.6.0

🔗 References (4)