Executive brief
js-toml is a JavaScript library used to parse TOML configuration files. A prototype pollution vulnerability allows attackers to inject malicious TOML input that modifies global object properties, potentially leading to authentication bypasses, denial of service, or remote code execution in applications using the library to parse untrusted data.
Technical details
This vulnerability is a prototype pollution flaw (CWE-1321) in the js-toml TOML parser. When parsing TOML input containing the specially crafted key __proto__, the library incorrectly adds or modifies properties on the global Object.prototype. The vulnerability requires no authentication or user interaction and is triggered simply by parsing untrusted TOML input. While js-toml itself lacks vulnerable gadgets, attackers can exploit this in consuming applications—for example, bypassing authorization checks that test for properties like user.isAdmin. The patch is available in version 1.0.2; all prior versions are vulnerable.
Affected products
- js-toml js-toml < 1.0.2
Timeline
- 2025-08-04: disclosed: Advisory published
- 2025-08-04: patched: Patch released in version 1.0.2