HIGHnpm
GHSA-65fc-cr5f-v7r2· CVE-2025-54803js-toml Prototype Pollution Vulnerability
Modified: 8/5/2025
package
pkg:npm/js-toml
js-toml Prototype Pollution Vulnerability
Modified: 8/5/2025
js-toml has silent type confusion via falsy-primitive duplicate-key bypass
Modified: 7/21/2026
js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
Modified: 6/26/2026