Vulnerability GHSA-p6vx-979v-rg4c

Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
7 hours ago
October 05, 2026 at 11:40 PM UTC
Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
0.12.0 - 1.6.1
0.12.0 - 1.6.1

Summary

Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)

Details

A fulfilled Promise node deserialized by fromJSON() can trigger unintended invocation of a plugin-produced callable through native ECMAScript thenable assimilation. This bypasses the type-confusion fix in [email protected] (GHSA-mv8w-475r-vwqw / CVE-2026-59940) and affects every plugin-capable release from 0.12.0 through the current 1.6.0.

Impacted packages

Timeline

Published
7 hours ago
October 05, 2026 at 11:40 PM UTC
Fixed (1.6.2)
2 months ago
August 04, 2026 at 03:38 AM UTC
Last Modified
7 hours ago
October 06, 2026 at 12:00 AM UTC