CVE-2026-82404 | toon-format toon up to 2.3.0 Decode expand.ts insertPathSafe prototype pollution
A vulnerability, which was classified as critical, was found in toon-format toon up to 2.3.0. This affects the function insertPathSafe of the file packages/toon/src/decode/expand.ts of the component Decode. Such manipulation leads to improperly controlled modification of object prototype attributes.
This vulnerability is documented as CVE-2026-82404. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More