Seroval Advisory Bypassed: New Promise-Thenable Flaw Lets fromJSON() Trigger Arbitrary Plugin Callables (CVE-2026-104846)
What happened
According to a GHSA advisory published October 5, 2026, researchers found that seroval's fromJSON() deserializer can be tricked into invoking a plugin-produced callable via native ECMAScript thenable assimilation when processing a fulfilled Promise node. The advisory states this is a bypass of the earlier type-confusion fix shipped in [email protected] (GHSA-mv8w-475r-vwqw / CVE-2026-59940), and that it affects every plugin-capable release from 0.12.0 through the current 1.6.0. The issue has been assigned CVE-2026-104846, carries a reported CVSS of 9.8, and a public proof-of-concept is noted as available.
Why it matters
seroval is used to serialize/deserialize JavaScript values (including Promises) across npm-based applications; any project that passes untrusted or semi-trusted serialized payloads into fromJSON() with plugins enabled is potentially exposed. Because this bypasses a prior fix for a related vulnerability, teams that previously remediated GHSA-mv8w-475r-vwqw may incorrectly believe they are already protected. The combination of a critical CVSS score, a public PoC, and broad version applicability (spanning over a year of releases) makes this a high-priority item for any dependency tree that includes seroval.
What defenders should watch for
- Inventory dependency trees for
serovalversions 0.12.0–1.6.0, including transitive dependencies pulled in by meta-frameworks or serialization libraries. - Identify any code path that calls
fromJSON()on data that originates from a network request, user input, or any source outside full trust boundaries. - Flag applications that register or load seroval plugins, since the vulnerable behavior depends on plugin-produced callables.
- Watch for unexpected function invocations or anomalous process behavior in application logs that correlate with deserialization of Promise-shaped objects.
- Treat the prior GHSA-mv8w-475r-vwqw patch as insufficient on its own — confirm whether a fixed release addressing this new bypass has been published before considering the issue closed.
Developing situation
This is net-new intelligence published same-day; a fix version was not confirmed in the available reporting at the time of this writing, so teams should monitor the advisory directly for remediation guidance. Full details: GHSA-p6vx-979v-rg4c.