CVE-2026-104846

Description

A type confusion vulnerability was found in the seroval npm package. The fromJSON() deserialization function, when processing a fulfilled Promise control node, can pass a plugin-produced callable-bearing thenable to a native ECMAScript Promise resolver. Thenable assimilation then invokes the callable unexpectedly, allowing attacker-controlled JSON to trigger code execution in applications using plugin-capable seroval releases (versions 0.12.0 through 1.6.1). This issue bypasses the Promise resolver type-confusion fix in version 1.5.3 (CVE-2026-59940) because the invocation occurs through native Promise settlement after the referenced value is deserialized.

Statement

A type confusion flaw was found in seroval, an npm library for JavaScript value serialization. When deserializing JSON via fromJSON(), a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. ECMAScript thenable assimilation then invokes the callable unexpectedly, allowing attacker-controlled JSON to trigger unintended code execution in applications that use seroval with plugins. This issue is a bypass of the fix for CVE-2026-59940, which addressed a related type-confusion in the Promise resolver path. The new exploitation vector operates through native Promise settlement after the referenced value is deserialized, circumventing the earlier guard. Red Hat Ansible Automation Orchestrator ships seroval 1.5.6 with seroval-plugins as a production dependency in the automation-orchestrator-ui container. Exploitation requires an authenticated attacker to inject crafted serialized JSON into a code path that calls fromJSON().

Mitigation

Update the seroval package to version 1.6.2 or later, which adds an isThennable() guard that rejects deserialized Promise values with a .then method.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.1N/A9.8
Attack VectorNetworkN/ANetwork
Attack ComplexityHighN/ALow
Privileges RequiredLowN/ANone
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityHighN/AHigh
Integrity ImpactHighN/AHigh
Availability ImpactLowN/AHigh

Vector

Red Hat: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L

cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Understanding the Weakness (CWE)

Availability,Integrity,Confidentiality

Technical Impact: Read Memory; Modify Memory; Execute Unauthorized Code or Commands; DoS: Crash, Exit, or Restart

When a memory buffer is accessed using the wrong type, it could read or write memory out of the bounds of the buffer, if the allocated buffer is smaller than the type that the code is attempting to access, leading to a crash and possibly code execution.

Frequently Asked Questions

Want to get errata notifications? Sign up here.