GHSA-p95v-992w-h6c3

    Dashboard / Vulnerabilities / GHSA-p95v-992w-h6c3

    GHSA-p95v-992w-h6c3

    Published: 3 Sept 2026Last Modified: 3 Sept 2026

    Summary: TOON: Prototype pollution when decoding untrusted TOON input

    Details: ### Summary Decoding attacker-controlled TOON containing a `__proto__`, `constructor`, or `prototype` key wrote through the object's prototype chain instead of creating an own property, polluting `Object.prototype` for the whole runtime. The `expandPaths: 'safe'` path (dotted keys such as `a.__proto__.x`) was the strongest vector; plain nested objects, tabular rows, and quoted keys were all affected. The encoder had a matching defect: it silently dropped own `__proto__` properties and could fire an inherited setter while normalizing. ### Impact Any service that decodes untrusted TOON is affected. Prototype pollution can escalate to denial of service or, with a suitable downstream gadget, remote code execution. ### Patches Upgrade to `@toon-format/[email protected]`. Decoders now materialize `__proto__`/`constructor`/`prototype` as ordinary own data properties, matching `JSON.parse` semantics; the encoder preserves the same keys without invoking inherited accessors. ### Workarounds None. Upgrade is the only fix. Callers who cannot upgrade should reject input whose keys include `__proto__`, `constructor`, or `prototype` before decoding. ### Port maintainers The same bug shape can exist in any implementation that assigns decoded keys with `obj[key] = value`. Rust, Swift, Java, Python, and C# ports should audit their object-construction and path-expansion paths for the three prototype keys.

    Affected packages

    Package

    Name: @toon-format/toon

    Purl: pkg:npm/%40toon-format/toon

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.3.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High