External risk intelligence

Seroval Promise Resolver Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-104846

Seroval is a software library used for JavaScript object serialization and deserialization. It is a build-time or runtime dependency embedded within applications rather than a standalone network-accessible service, appliance, or edge gateway. Consequently, it is not directly reachable from the public internet in typical deployments.

Deserialization

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Seroval library, which handles JavaScript data processing. This flaw could allow an attacker to execute arbitrary code within applications using affected versions of Seroval, potentially leading to a significant compromise of system integrity and data. The main concern is confirming relevance and exposure.

  • Library flaw enables unexpected code execution.
  • Matters for applications handling untrusted data.
  • Confirm usage and assess potential impact.

Attack Path

How an attacker could exploit the issue

An attacker can trigger this vulnerability by sending specially crafted data to an application that uses a vulnerable version of Seroval. If the application deserializes this data, it can lead to unexpected code execution.

  • Unauthenticated network access needed.
  • Malicious data deserialization.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, applications using plugin-capable Seroval releases could allow attacker-controlled input to trigger unexpected code execution. This occurs because a fulfilled Promise control node's `fromJSON` deserialization may pass a plugin-produced thenable to a native Promise resolver, leading to unintended callable invocation.

  • Application code execution.
  • Malicious input via deserialization.
  • Compromised application behavior.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Seroval likely impacts application owners and the platform teams responsible for managing shared libraries. The immediate first step is to identify all applications using vulnerable versions of Seroval, confirm their exposure and business criticality, and then engage the relevant application owners to plan remediation.

  • Application owners should take ownership.
  • Verify Seroval usage and exposure.
  • Plan coordinated updates and testing.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Seroval library?

Seroval is a JavaScript utility designed to transform complex data structures into strings and back again, offering capabilities that exceed standard JSON serialization. Developers often include it as a library or dependency within their web applications to manage sophisticated object graphs, such as those involving Promises or specific plugin-defined types, during data processing.

What does CWE-843 mean for CVE-2026-104846?

CWE-843, or Type Confusion, occurs when software accesses a resource using an incompatible type. In this vulnerability, Seroval mistakenly treats data provided by an attacker as a safe object, allowing it to interact with the JavaScript environment's internal Promise handling in a way that triggers unintended functions or code execution.

How can an attacker trigger this vulnerability?

An attacker must provide specially crafted JSON data to an application that uses a plugin-capable version of Seroval. This input must be processed by the application's deserialization routine. If the input is not processed or deserialized, the trigger path is not activated, as the flaw relies on the library's internal handling of fulfilled Promise control nodes.

Is my application reachable from the internet?

According to Halo Surface Signal, Seroval is a library embedded within your application code rather than a standalone network service. Because it is not an internet-facing gateway or appliance, its reachability depends entirely on whether your application accepts and deserializes untrusted user input from external sources.

How do I address CVE-2026-104846?

The primary response is to update your project's dependencies to use Seroval version 1.6.2 or later, which contains the fix for this issue. Before updating, developers should audit their codebase to identify where the library is utilized and confirm that the application environment is prepared to handle the dependency change through standard testing procedures.

References