CRITICAL
9.8 CVE-2026-59940 Published 18 Aug 2026
Seroval fromJSON Deserialization Side-Effect RCE Vulnerability
Worried this affects your website?
seroval, a JavaScript value stringification library, supports complex structures beyond JSON.stringify capabilities.
Prior to version 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records. This is a deserialization side-effect vulnerability that can cause unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers.
- Affected versions: before 1.5.3
- Requires plugins enabled
- Potential impact: unintended server-side invocation or RCE when downstream frameworks register callable wrappers
This issue is fixed in version 1.5.3.
Reference: CVE-2026-59940 on NVD
← Back to Security News