JS Value Stringification Vulnerability in Seroval by lxsmnsyc
CVE-2026-104846

9.8CRITICAL

Key Information:

Vendor

Lxsmnsyc

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104846?

The Seroval library, used for JS value stringification, is vulnerable to a security issue that allows attacker-controlled JSON to trigger unexpected code execution in applications. This occurs between versions 0.12.0 and 1.6.1, where the deserialization of a fulfilled Promise control node can inadvertently pass a plugin-generated callable to a native Promise resolver. This unexpected invocation allows attackers to exploit applications leveraging Seroval's plugin capabilities, circumventing previous protections developed for similar issues. The vulnerability has been resolved in version 1.6.2.

Affected Version(s)

seroval >= 0.12.0, < 1.6.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.