{"id":"GHSA-p6vx-979v-rg4c","summary":"Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)","details":"A fulfilled Promise node deserialized by `fromJSON()` can trigger unintended invocation of a plugin-produced callable through native ECMAScript thenable assimilation. This bypasses the type-confusion fix in `seroval@1.5.3` (GHSA-mv8w-475r-vwqw / CVE-2026-59940) and affects every plugin-capable release from `0.12.0` through the current `1.6.0`.","aliases":["CVE-2026-104846"],"modified":"2026-10-06T00:00:08.435171324Z","published":"2026-10-05T23:40:43Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-10-05T23:40:43Z","nvd_published_at":"2026-10-02T16:16:47Z","cwe_ids":["CWE-843"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-p6vx-979v-rg4c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104846"},{"type":"WEB","url":"https://github.com/lxsmnsyc/seroval/commit/f1ffcc96d259f9b5b3d71feb262b58240c90e7b7"},{"type":"PACKAGE","url":"https://github.com/lxsmnsyc/seroval"}],"affected":[{"package":{"name":"seroval","ecosystem":"npm","purl":"pkg:npm/seroval"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.12.0"},{"fixed":"1.6.2"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.6.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-p6vx-979v-rg4c/GHSA-p6vx-979v-rg4c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}