Serialization Vulnerability in TOON by Toon Format
CVE-2026-82404

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-82404?

The TOON library, used for human-readable serialization of JSON data, contains a vulnerability allowing attacker-controlled data to write through the object prototype chain. This affects services decoding untrusted TOON, potentially causing denial of service or remote code execution in the presence of downstream vulnerabilities. Key vectors include dotted keys that manipulate Object.prototype, making various configurations susceptible. The issue is addressed in versions 2.3.1 and above, emphasizing the importance of updating software to protect against this risk.

Affected Version(s)

toon < 2.3.1

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.