GHSA-p6vx-979v-rg4cCriticalCVSS 9.8
Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
🔗 CVE IDs covered (1)
📋 Description
A fulfilled Promise node deserialized by fromJSON() can trigger unintended invocation of a plugin-produced callable through native ECMAScript thenable assimilation. This bypasses the type-confusion fix in [email protected] (GHSA-mv8w-475r-vwqw / CVE-2026-59940) and affects every plugin-capable release from 0.12.0 through the current 1.6.0.
🎯 Affected products1
- npm/seroval:>= 0.12.0, <= 1.6.0