Executive brief
js-toml is a JavaScript library for parsing TOML configuration files. A flaw in versions before 1.1.3 allows attacker-controlled input with deeply nested structures to crash the parser by exhausting the call stack, causing denial of service to applications that rely on it.
Technical details
The recursive parser and interpreter in js-toml do not bound nesting depth for arrays, inline tables, or dotted keys, allowing deeply nested or complex input to exhaust the V8 call stack and throw an uncaught RangeError instead of the documented SyntaxParseError. Applications that parse untrusted TOML and only catch SyntaxParseError will propagate the unexpected exception, terminating the process. Version 1.1.3 adds configurable recursion depth limits (default 100) and converts residual RangeErrors to SyntaxParseError.
Affected products
- sunnyadn js-toml before 1.1.3
Timeline
- 2026-09-22: disclosed
- 2026-06-30: patched