Product
The @toon-format/toon library fails to sanitize input, allowing attackers to pollute the Object prototype via __proto__, constructor, or prototype keys, which can lead to denial of service or remote code execution.