Intel

AIKIDO-2026-830881

seroval-plugins is vulnerable to Type Confusion

Type ConfusionGHSA-8q2v-cx68-9v9h Published 2 days ago

65

Medium Risk

This Affects:

JSseroval-plugins
1.5.0 - 1.6.4
Fixed in 1.6.5
Are you affected? Scan for Free

TL;DR

AbortSignalPlugin.deserialize in seroval-plugins passes a deserialized reference table value to PROMISE_TO_ABORT_SIGNAL as a Promise without checking that it is one, and that helper calls promise.then(abort, abort) synchronously during fromJSON. A crafted Reference node that points at an application object with a then method causes that method to run during deserialization. That then method only receives seroval's own bound AbortController.abort, so the impact is weaker than the ReadableStream and Promise resolver confusion in the same package. The fix checks that the value is an actual Promise before calling then on it.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use seroval-plugins' AbortSignalPlugin to deserialize untrusted payloads.

Background info

seroval-plugins is vulnerable to Type Confusion in versions 1.5.0 - 1.6.4.

How to fix this

Upgrade the seroval-plugins library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform