Serialization Vulnerability in TOON by Toon Format
CVE-2026-82404
8.3HIGH
What is CVE-2026-82404?
The TOON library, used for human-readable serialization of JSON data, contains a vulnerability allowing attacker-controlled data to write through the object prototype chain. This affects services decoding untrusted TOON, potentially causing denial of service or remote code execution in the presence of downstream vulnerabilities. Key vectors include dotted keys that manipulate Object.prototype, making various configurations susceptible. The issue is addressed in versions 2.3.1 and above, emphasizing the importance of updating software to protect against this risk.
Affected Version(s)
toon < 2.3.1
