JS Value Stringification Vulnerability in Seroval by lxsmnsyc
CVE-2026-104846
9.8CRITICAL
What is CVE-2026-104846?
The Seroval library, used for JS value stringification, is vulnerable to a security issue that allows attacker-controlled JSON to trigger unexpected code execution in applications. This occurs between versions 0.12.0 and 1.6.1, where the deserialization of a fulfilled Promise control node can inadvertently pass a plugin-generated callable to a native Promise resolver. This unexpected invocation allows attackers to exploit applications leveraging Seroval's plugin capabilities, circumventing previous protections developed for similar issues. The vulnerability has been resolved in version 1.6.2.
Affected Version(s)
seroval >= 0.12.0, < 1.6.2
