{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/toon--2.3.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:toon-format:toon:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-82404"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["toon (\u003c 2.3.1)"],"_cs_severities":["high"],"_cs_tags":["prototype-pollution","supply-chain","deserialization"],"_cs_type":"threat","_cs_vendors":["toon-format"],"content_html":"\u003cp\u003eThe TOON format library, specifically \u003ccode\u003e@toon-format/toon\u003c/code\u003e versions prior to 2.3.1, is vulnerable to prototype pollution when decoding untrusted input. The flaw arises because the library's decoder fails to differentiate between own properties and inherited properties when parsing objects. An attacker supplying input containing \u003ccode\u003e__proto__\u003c/code\u003e, \u003ccode\u003econstructor\u003c/code\u003e, or \u003ccode\u003eprototype\u003c/code\u003e keys can cause the library to write these keys into the JavaScript \u003ccode\u003eObject.prototype\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eThis behavior affects both the \u003ccode\u003eexpandPaths: 'safe'\u003c/code\u003e path, which handles dotted keys, and standard nested objects, tabular rows, or quoted keys. Furthermore, the encoder is also defective, silently dropping legitimate own \u003ccode\u003e__proto__\u003c/code\u003e properties and potentially triggering inherited setters during normalization. Successful exploitation allows for the alteration of the runtime environment, which can be leveraged to cause application crashes (denial of service) or, if the application environment contains reachable gadgets, remote code execution. No workarounds exist for this vulnerability; users must upgrade to version 2.3.1 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eAny service that decodes untrusted TOON input is vulnerable to this prototype pollution attack. Depending on the downstream logic of the host application, this vulnerability can lead to critical security outcomes, including service disruption through denial of service or full system compromise via remote code execution by leveraging gadget chains. The library is commonly used for data interchange, making the scope of potential exploitation wide for any application relying on this package for serialization or deserialization tasks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003e@toon-format/toon\u003c/code\u003e package to version 2.3.1 or later to remediate CVE-2026-82404.\u003c/li\u003e\n\u003cli\u003eImplement a pre-decoding validation step to inspect input for the presence of '\u003cstrong\u003eproto\u003c/strong\u003e', 'constructor', or 'prototype' keys if an immediate upgrade is not possible.\u003c/li\u003e\n\u003cli\u003eAudit other implementations or language ports of the TOON format (such as those in Rust, Swift, Java, Python, or C#) for similar unsafe object-construction patterns where keys are assigned directly to objects without validation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T00:07:00Z","date_published":"2026-09-04T00:07:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-toon-prototype-pollution/","summary":"The @toon-format/toon library fails to sanitize input, allowing attackers to pollute the Object prototype via __proto__, constructor, or prototype keys, which can lead to denial of service or remote code execution.","title":"Prototype Pollution in @toon-format/toon","url":"https://feed.craftedsignal.io/briefs/2026-09-toon-prototype-pollution/"}],"language":"en","title":"CraftedSignal Threat Feed - Toon (\u003c 2.3.1)","version":"https://jsonfeed.org/version/1.1"}