Sceawere
Vulnerability Detail
CVE-2026-104846UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Seroval Deserialization Code Execution
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 7h ago
- Vendor
- lxsmnsyc
- Product
- seroval
- Attack Type
- CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. ECMAScript thenable assimilation then invokes the callable unexpectedly, allowing attacker-controlled JSON to trigger code in applications using plugin-capable Seroval releases. This path bypasses the Promise resolver type-confusion remediation in version 1.5.3 for CVE-2026-59940 because the unexpected invocation occurs through native Promise settlement after the referenced value is deserialized. This issue is fixed in version 1.6.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-02T16:16:47.230Z",
"pubdate": "2026-10-02T16:16:47.230Z",
"executiveSummary": "A critical deserialization vulnerability exists in Seroval, a JavaScript serialization library, spanning versions 0.12.0 up to 1.6.2. The security flaw is located within the fromJSON deserialization process when handling a fulfilled Promise control node. An attacker can exploit this issue by supplying a crafted JSON payload containing a plugin-produced, callable-bearing thenable object. When this object is deserialized and passed to a native Promise resolver, the ECMAScript thenable assimilation process unexpectedly executes the attacker-controlled callable code.\nThis vulnerability effectively bypasses the Promise resolver type-confusion remediation implemented in version 1.5.3 for CVE-2026-59940 because the malicious invocation occurs during native Promise settlement after deserialization of the referenced value. The vulnerability allows arbitrary code execution on the host environment running plugin-capable Seroval instances. Exploitation requires the application to process untrusted JSON inputs via Seroval's fromJSON function. The vulnerability has been fully patched in Seroval version 1.6.2.",
"technicalDetails": "The vulnerability resides within Seroval's deserialization engine, specifically affecting the fromJSON handler when processing serialized Promise control nodes in plugin-capable configurations from version 0.12.0 until 1.6.2. Seroval supports complex JavaScript structures beyond standard JSON capabilities, allowing plugins to generate custom object representations during deserialization. Under vulnerable conditions, an active plugin can produce a thenable object—an object exposing a callable 'then' method—which is subsequently passed to a native Promise resolver during the deserialization of a fulfilled Promise node.\nThis behavior exposes a design flaw related to native ECMAScript thenable assimilation. According to the ECMAScript standard, when a native Promise resolver is resolved with a thenable object, the engine must assimilate it by immediately invoking its 'then' method. Because the deserialized object contains an attacker-controlled callable inside this thenable structure, the native JavaScript runtime executes the function unexpectedly. This execution path bypasses the validation and type-confusion defenses introduced in version 1.5.3 for CVE-2026-59940. The bypass succeeds because the type-confusion checks are executed during the deserialization phase, whereas the unexpected execution occurs during the subsequent native Promise settlement phase after the value has already been successfully deserialized.\nThe step-by-step attack flow proceeds as follows:\n1. An attacker constructs a malicious JSON payload designed to represent a serialized, fulfilled Promise control node.\n2. The payload specifies structural properties that, when processed by a plugin-capable Seroval instance, reconstruct a custom thenable object embedding a malicious callable payload.\n3. The application passes this untrusted JSON payload to the fromJSON deserializer.\n4. Seroval deserializes the fulfilled Promise node and yields the plugin-produced callable-bearing thenable to the native Promise resolver.\n5. The JavaScript runtime performs thenable assimilation on the native Promise, triggering the automatic execution of the callable function embedded in the thenable.\n6. Arbitrary attacker-specified code runs within the context of the application process.\nExploitation does not require prior authentication or elevated privileges, provided the application exposes an endpoint that passes input directly to Seroval's fromJSON. The post-exploitation impact includes potential remote code execution, full compromise of the application environment, and unauthorized access to system resources depending on the privileges of the executing Node.js or JavaScript runtime."
}