<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T11:13:15.760232+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364165</id>
    <title>EUVD-2026-364165</title>
    <updated>2026-10-07T11:13:15.800368+00:00</updated>
    <content>EUVD-2026-364165</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63376</id>
    <title>fkie_cve-2026-63376</title>
    <updated>2026-10-07T11:13:15.800407+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking value uses both arrays and strings, so valueAssignments records a comma-joined path such as a,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate-key guard to miss and attacker-controlled keys to be written to Object.prototype. A table-array prefix-clearing path in addTableArray can also erase guard state before the same __proto__ traversal. Injected properties become visible throughout the Node.js process and can cause denial of service, logic or authorization bypass, or code execution when an application contains a suitable gadget. This issue is fixed in version 4.1.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63376"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v5mp-jgw5-2x6j</id>
    <title>GHSA-v5mp-jgw5-2x6j — toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization</title>
    <updated>2026-10-07T11:13:15.800443+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: toml</p>
<p>### Summary</p>
<p>`toml.parse()` writes attacker-controlled keys onto `Object.prototype`. The compiler protects the tables it builds by creating them with `Object.create(null)`, which neutralizes a direct `[__proto__]` table. An attacker bypasses that protection by routing a table path *through a scalar value* and into the real prototype chain: a path such as `a.b.y.__proto__.__proto__`, where `a.b.y` holds a number, resolves to `Object.prototype` and every subsequent key/value writes onto it.</p>
<p>The bypass succeeds because the compiler's duplicate-key guards track paths with keys that do not match the keys used during traversal. The tracking strings and the traversal strings **desynchronize**, so the guard that should reject descending through an existing scalar never fires.</p>
<p>### Steps to reproduce</p>
<p>1. Install the latest version and run the comma-desynchronization payload.</p>
<p>```bash
   npm install toml@4.1.1
   ```</p>
<p>```js
   const toml = require("toml");
   delete Object.prototype.polluted;</p>
<p>toml.parse(`
   [a.b]
   y = 1
   [a.b.y.__proto__.__proto__]
   polluted = "yes"
   `);</p>
<p>console.log(({}).polluted);   // -&gt; "yes"
   ```</p>
<p>2. Observe that a freshly created object inherits the injected key, confirming `Object.prototype` was modified:</p>
<p>```
   yes
   ```</p>
<p>3. Confirm the prefix-clear variant reaches the same result:</p>
<p>```js
   toml.parse(`
   aa = 1
   [[a]]
   [aa.__proto__.__proto__]
   polluted = "yes"
   `);
   console.log(({}).polluted);   // -&gt; "yes"
   ```…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v5mp-jgw5-2x6j"/>
  </entry>
</feed>
