CRITICAL 9.8 CVE-2026-59940 Published 18 Aug 2026

Seroval fromJSON Deserialization Side-Effect RCE Vulnerability

Worried this affects your website?

seroval, a JavaScript value stringification library, supports complex structures beyond JSON.stringify capabilities.

Prior to version 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records. This is a deserialization side-effect vulnerability that can cause unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers.

  • Affected versions: before 1.5.3
  • Requires plugins enabled
  • Potential impact: unintended server-side invocation or RCE when downstream frameworks register callable wrappers

This issue is fixed in version 1.5.3.

Reference: CVE-2026-59940 on NVD

← Back to Security News