Vulnerability GHSA-p6vx-979v-rg4c
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
7 hours ago
October 05, 2026 at 11:40 PM UTC
Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
0.12.0 - 1.6.1
0.12.0 - 1.6.1
Summary
Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
Details
A fulfilled Promise node deserialized by fromJSON() can trigger unintended invocation of a plugin-produced callable through native ECMAScript thenable assimilation. This bypasses the type-confusion fix in [email protected] (GHSA-mv8w-475r-vwqw / CVE-2026-59940) and affects every plugin-capable release from 0.12.0 through the current 1.6.0.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
7 hours ago
Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization
0.1.0 - 1.6.2 GHSA-jp82-f5mq-hwhp
0.1.0 - 1.6.2 GHSA-jp82-f5mq-hwhp
Critical
2 months ago
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
0.1.0 - 1.5.2 GHSA-mv8w-475r-vwqw
0.1.0 - 1.5.2 GHSA-mv8w-475r-vwqw
High Risk
8 months ago
Seroval affected by Denial of Service via Deeply Nested Objects
0.1.0 - 1.4.0 GHSA-3j22-8qj3-26mx
0.1.0 - 1.4.0 GHSA-3j22-8qj3-26mx
High Risk
8 months ago
Seroval affected by Denial of Service via Array serialization
0.1.0 - 1.4.0 GHSA-66fc-rw6m-c2q6
0.1.0 - 1.4.0 GHSA-66fc-rw6m-c2q6
High Risk
8 months ago
seroval affected by Denial of Service via RegExp serialization
0.2.0 - 1.4.0 GHSA-hx9m-jf43-8ffr
0.2.0 - 1.4.0 GHSA-hx9m-jf43-8ffr
Impacted packages
Timeline
Published
7 hours ago
October 05, 2026 at 11:40 PM UTC
Fixed (1.6.2)
2 months ago
August 04, 2026 at 03:38 AM UTC
Last Modified
7 hours ago
October 06, 2026 at 12:00 AM UTC