Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104846— Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of CVE-2026-59940)

Quick assessment

Affected
lxsmnsyc seroval
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Seroval 支持 JavaScript 值的字符串化,包括超出 JSON.stringify 能力的复杂结构。从版本 0.12.0 到 1.6.2, 在反序列化一个已解决的 Promise 控制节点时,可能将一个由插件生成的、包含可调用对象的 thenable 传递给原生的 Promise 解析器。根据 ECMAScript 规范,thenable 的合并机制会意外调用该可调用对象,从而使攻击者可控的 JSON 数据能够触发使用支持插件功能的 Seroval 版本的应用程序中的代码执行。此路径绕过了版本 1.5

CVSS 9.8 · Critical

Affected Version Matrix 1

VendorProduct Version RangeStatus
lxsmnsyc seroval >= 0.12.0, < 1.6.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104846

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of CVE-2026-59940)
Source: CVE Program / CVE List V5
Vulnerability Description
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. ECMAScript thenable assimilation then invokes the callable unexpectedly, allowing attacker-controlled JSON to trigger code in applications using plugin-capable Seroval releases. This path bypasses the Promise resolver type-confusion remediation in version 1.5.3 for CVE-2026-59940 because the unexpected invocation occurs through native Promise settlement after the referenced value is deserialized. This issue is fixed in version 1.6.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
lxsmnsyc seroval >= 0.12.0, < 1.6.2 -

II. Public POCs for CVE-2026-104846

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104846

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104846 (1)

Vendor Advisories for CVE-2026-104846 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104846

No comments yet


Leave a comment