Sunnyadn

Js-toml

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.51%
  • Veröffentlicht 22.09.2026 19:16:44
  • Zuletzt bearbeitet 26.09.2026 01:17:01

js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does not bound nesting or dotted-key depth in the recursive parser at src/load/parser.ts or the interpreter at src/load/interpreter.ts, so deeply nested arrays, deeply nested inline tabl...

  • EPSS 0.23%
  • Veröffentlicht 14.08.2026 19:17:18
  • Zuletzt bearbeitet 18.09.2026 20:09:01

js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with `if (object[key])` instead of `if (key in object)`. When the prior value is a falsy primitive — `fal...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 19.06.2026 18:14:20
  • Zuletzt bearbeitet 26.06.2026 12:11:46

js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 parse hexadecimal / octal / binary integer literals via a hand-written `parseBigInt` loop that multiplies a `BigInt` accumulator by ...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 05.08.2025 00:06:15
  • Zuletzt bearbeitet 09.10.2025 17:32:53

js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype pollution vulnerability in js-toml allows a remote attacker to add or modify properties of the global Object.prototype by parsing ...