CVE-2026-82404 | toon-format toon up to 2.3.0 Decode expand.ts insertPathSafe prototype pollution

SecurityVulns

A vulnerability, which was classified as critical, was found in toon-format toon up to 2.3.0. This affects the function insertPathSafe of the file packages/toon/src/decode/expand.ts of the component Decode. Such manipulation leads to improperly controlled modification of object prototype attributes.

This vulnerability is documented as CVE-2026-82404. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More