Executive Summary

A critical deserialization vulnerability (CVE-2026-104846) with a CVSS score of 9.8 affects Seroval, a JavaScript library for stringifying complex structures. The vulnerability allows attackers to execute arbitrary code by providing malicious JSON input to applications using vulnerable Seroval versions (0.12.0 to 1.6.1). The issue is fixed in version 1.6.2.

Technical Analysis

The vulnerability class is a deserialization issue. Seroval's fromJSON deserialization function fails to properly handle fulfilled Promise control nodes. Specifically, it can pass a plugin-produced callable-bearing thenable to a native Promise resolver. This leads to unexpected invocation of the callable when the deserialized value is settled, allowing attackers to execute code.

How It Gets Exploited

An attacker can exploit this vulnerability by crafting malicious JSON input that, when deserialized by a vulnerable Seroval version, triggers code execution. The process involves:

  • The attacker prepares a specially crafted JSON payload containing a fulfilled Promise control node with a callable-bearing thenable.
  • The attacker sends this payload to the vulnerable application, which uses Seroval for deserialization.
  • Seroval deserializes the payload and passes the callable-bearing thenable to a native Promise resolver.
  • When the Promise is settled, the native Promise resolver invokes the callable unexpectedly, executing the attacker's code.

Impact Assessment

The impact is severe: an attacker can achieve arbitrary code execution (RCE) on the affected system. The vulnerability affects Seroval versions from 0.12.0 to 1.6.1. The CVSS score of 9.8 indicates critical severity, with high impacts on confidentiality, integrity, and availability.

Recommended Actions

To mitigate this vulnerability:

  • Update Seroval to version 1.6.2 or later.
  • Implement input validation and sanitization for JSON data to prevent malicious payloads from being deserialized.
  • Monitor for suspicious activity and implement detection rules to identify potential exploitation attempts.

Sources