Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mv8w-475r-vwqw | seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization |
Tue, 18 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lxsmnsyc
Lxsmnsyc seroval |
|
| Vendors & Products |
Lxsmnsyc
Lxsmnsyc seroval |
Tue, 18 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers. This issue is fixed in version 1.5.3. | |
| Title | Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization | |
| Weaknesses | CWE-502 CWE-843 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-18T15:49:59.261Z
Reserved: 2026-07-07T18:20:06.127Z
Link: CVE-2026-59940
No data.
Status : Received
Published: 2026-08-18T15:16:56.007
Modified: 2026-08-18T16:18:11.377
Link: CVE-2026-59940
No data.
OpenCVE Enrichment
Updated: 2026-08-18T19:00:10Z
Github GHSA