CYBER CODE RED

Get real-time updates on Telegram

P4Verified

Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)

CVE-2026-104846 affects seroval. CVSS base score 9.8 (CRITICAL, Vendor/CNA). EPSS 0.00345 (percentile 0.25722), scored 2026-10-04. Affected range: >= 0.12.0, <= 1.6.0. Fixed version: 1.6.2.

Published

CVE
CVE-2026-104846
CWE
CWE-843
Product
seroval
CCR priority
39.3 /100 (P4)
CVSS
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · Vendor/CNA
EPSS
0.00345 · percentile 0.25722 · 2026-10-04
KEV
no

Affected products

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-104846.html