seroval-plugins is vulnerable to Type Confusion
65
Medium Risk
AbortSignalPlugin.deserialize in seroval-plugins passes a deserialized reference table value to PROMISE_TO_ABORT_SIGNAL as a Promise without checking that it is one, and that helper calls promise.then(abort, abort) synchronously during fromJSON. A crafted Reference node that points at an application object with a then method causes that method to run during deserialization. That then method only receives seroval's own bound AbortController.abort, so the impact is weaker than the ReadableStream and Promise resolver confusion in the same package. The fix checks that the value is an actual Promise before calling then on it.
You are affected if you are using a version that falls within the vulnerable range and you use seroval-plugins' AbortSignalPlugin to deserialize untrusted payloads.
seroval-plugins is vulnerable to Type Confusion in versions 1.5.0 - 1.6.4.
Upgrade the seroval-plugins library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.