Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-59940— Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization

Quick assessment

Affected
lxsmnsyc seroval
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Seroval 支持 JavaScript 值的字符串化,包括超越 JSON.stringify 能力范围的复杂结构。在 1.5.3 版本之前,seroval.fromJSON() 允许攻击者控制的 JSON Promise 控制节点,在未验证真实内部 Promise 解析器记录的情况下,对通用反序列化引用表中的值进行操作。当启用插件时,这会导致反序列化副作用;若下游框架注册了可调用包装器,则可能引发非预期的服务器端调用或远程代码执行。该问题已在 1.5.3 版本中修复。

CVSS 9.8 · Critical EPSS 0.81% · P54

Affected Version Matrix 1

VendorProduct Version RangeStatus
lxsmnsyc seroval < 1.5.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-59940

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
Source: CVE Program / CVE List V5
Vulnerability Description
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers. This issue is fixed in version 1.5.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
lxsmnsyc seroval < 1.5.3 -

II. Public POCs for CVE-2026-59940

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-59940

登录查看更多情报信息。

Vendor Advisories for CVE-2026-59940 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-59940

No comments yet


Leave a comment