{"id":"CVE-2026-63376","title":"toml-node is a TOML parser for Node.js and the browser","summary":"toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Ob…","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","cwe":["CWE-1321","CWE-915"],"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["enterprise_linux 10"],"patched":["toml 4.1.2"],"published":"2026-09-03","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:09:13.080","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63376","references":[{"url":"https://github.com/BinaryMuse/toml-node/commit/def6ab5ea99038c0dd482cd6af1745a6af8b4c44","label":"security-advisories@github.com"},{"url":"https://github.com/BinaryMuse/toml-node/commit/dfaff662276adc38a2e03df3139f7119b0185463","label":"security-advisories@github.com"},{"url":"https://github.com/BinaryMuse/toml-node/security/advisories/GHSA-v5mp-jgw5-2x6j","label":"security-advisories@github.com"},{"url":"https://github.com/BinaryMuse/toml-node/security/advisories/GHSA-v5mp-jgw5-2x6j","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-63376.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-63376"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2528256"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-63376"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63376"},{"url":"https://github.com/advisories/GHSA-v5mp-jgw5-2x6j"}],"tags":["nvd","csaf","vex","red-hat","ghsa","npm","score-dispute"],"epss":0.00383,"epssPercentile":0.3207,"aliases":["GHSA-v5mp-jgw5-2x6j"],"ecosystem":"npm","scores":{"nvd":8.2,"vendor":3.7,"ghsa":8.2},"ingestedAt":"2026-09-03T21:08:45.983Z","slug":"CVE-2026-63376","body":"## Overview\n\ntoml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking value uses both arrays and strings, so valueAssignments records a comma-joined path such as a,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate-key guard to miss and attacker-controlled keys to be written to Object.prototype. A table-array prefix-clearing path in addTableArray can also erase guard state before the same __proto__ traversal. Injected properties become visible throughout the Node.js process and can cause denial of service, logic or authorization bypass, or code execution when an application contains a suitable gadget. This issue is fixed in version 4.1.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-63376)\n\nAffected packages:\n\n- `toml < 4.1.2`\n\nPatched in:\n\n- `toml 4.1.2`\n\nSource: https://github.com/advisories/GHSA-v5mp-jgw5-2x6j\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10 · no fix planned: Red Hat Enterprise Linux 10 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-63376.json)","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":24945,"id":"CVE-2026-63376","ts":1788989016276,"field":"cvss","old":"3.7","new":"8.2"},{"seq":24944,"id":"CVE-2026-63376","ts":1788989016276,"field":"severity","old":"low","new":"high"},{"seq":24370,"id":"CVE-2026-63376","ts":1788985258267,"field":"cvss","old":"8.2","new":"3.7"},{"seq":24369,"id":"CVE-2026-63376","ts":1788985258267,"field":"severity","old":"high","new":"low"},{"seq":23700,"id":"CVE-2026-63376","ts":1788985200820,"field":"cvss","old":"3.7","new":"8.2"},{"seq":23699,"id":"CVE-2026-63376","ts":1788985200820,"field":"severity","old":"low","new":"high"},{"seq":22998,"id":"CVE-2026-63376","ts":1788981575657,"field":"cvss","old":"8.2","new":"3.7"},{"seq":22997,"id":"CVE-2026-63376","ts":1788981575657,"field":"severity","old":"high","new":"low"},{"seq":22353,"id":"CVE-2026-63376","ts":1788981332196,"field":"cvss","old":"3.7","new":"8.2"},{"seq":22352,"id":"CVE-2026-63376","ts":1788981332196,"field":"severity","old":"low","new":"high"},{"seq":21697,"id":"CVE-2026-63376","ts":1788977852022,"field":"cvss","old":"8.2","new":"3.7"},{"seq":21696,"id":"CVE-2026-63376","ts":1788977852022,"field":"severity","old":"high","new":"low"},{"seq":21071,"id":"CVE-2026-63376","ts":1788977455180,"field":"cvss","old":"3.7","new":"8.2"},{"seq":21070,"id":"CVE-2026-63376","ts":1788977455180,"field":"severity","old":"low","new":"high"},{"seq":20437,"id":"CVE-2026-63376","ts":1788974146200,"field":"cvss","old":"8.2","new":"3.7"},{"seq":20436,"id":"CVE-2026-63376","ts":1788974146200,"field":"severity","old":"high","new":"low"},{"seq":19818,"id":"CVE-2026-63376","ts":1788973593365,"field":"cvss","old":"3.7","new":"8.2"},{"seq":19817,"id":"CVE-2026-63376","ts":1788973593365,"field":"severity","old":"low","new":"high"},{"seq":19076,"id":"CVE-2026-63376","ts":1788969853957,"field":"cvss","old":"8.2","new":"3.7"},{"seq":19075,"id":"CVE-2026-63376","ts":1788969853957,"field":"severity","old":"high","new":"low"},{"seq":18499,"id":"CVE-2026-63376","ts":1788969749310,"field":"cvss","old":"3.7","new":"8.2"},{"seq":18498,"id":"CVE-2026-63376","ts":1788969749310,"field":"severity","old":"low","new":"high"},{"seq":17896,"id":"CVE-2026-63376","ts":1788966236176,"field":"cvss","old":"8.2","new":"3.7"},{"seq":17895,"id":"CVE-2026-63376","ts":1788966236176,"field":"severity","old":"high","new":"low"},{"seq":17356,"id":"CVE-2026-63376","ts":1788965878059,"field":"cvss","old":"3.7","new":"8.2"},{"seq":17355,"id":"CVE-2026-63376","ts":1788965878059,"field":"severity","old":"low","new":"high"},{"seq":16810,"id":"CVE-2026-63376","ts":1788962619612,"field":"cvss","old":"8.2","new":"3.7"},{"seq":16809,"id":"CVE-2026-63376","ts":1788962619612,"field":"severity","old":"high","new":"low"},{"seq":16345,"id":"CVE-2026-63376","ts":1788962031143,"field":"cvss","old":"3.7","new":"8.2"},{"seq":16344,"id":"CVE-2026-63376","ts":1788962031143,"field":"severity","old":"low","new":"high"},{"seq":15821,"id":"CVE-2026-63376","ts":1788958985667,"field":"cvss","old":"8.2","new":"3.7"},{"seq":15820,"id":"CVE-2026-63376","ts":1788958985667,"field":"severity","old":"high","new":"low"},{"seq":15411,"id":"CVE-2026-63376","ts":1788958167589,"field":"cvss","old":"3.7","new":"8.2"},{"seq":15410,"id":"CVE-2026-63376","ts":1788958167589,"field":"severity","old":"low","new":"high"},{"seq":15001,"id":"CVE-2026-63376","ts":1788955357002,"field":"cvss","old":"8.2","new":"3.7"},{"seq":15000,"id":"CVE-2026-63376","ts":1788955357002,"field":"severity","old":"high","new":"low"},{"seq":14591,"id":"CVE-2026-63376","ts":1788954317282,"field":"cvss","old":"3.7","new":"8.2"},{"seq":14590,"id":"CVE-2026-63376","ts":1788954317282,"field":"severity","old":"low","new":"high"},{"seq":14181,"id":"CVE-2026-63376","ts":1788951730205,"field":"cvss","old":"8.2","new":"3.7"},{"seq":14180,"id":"CVE-2026-63376","ts":1788951730205,"field":"severity","old":"high","new":"low"},{"seq":13771,"id":"CVE-2026-63376","ts":1788950466459,"field":"cvss","old":"3.7","new":"8.2"},{"seq":13770,"id":"CVE-2026-63376","ts":1788950466459,"field":"severity","old":"low","new":"high"},{"seq":13361,"id":"CVE-2026-63376","ts":1788948096223,"field":"cvss","old":"8.2","new":"3.7"},{"seq":13360,"id":"CVE-2026-63376","ts":1788948096223,"field":"severity","old":"high","new":"low"},{"seq":12951,"id":"CVE-2026-63376","ts":1788946607053,"field":"cvss","old":"3.7","new":"8.2"},{"seq":12950,"id":"CVE-2026-63376","ts":1788946607053,"field":"severity","old":"low","new":"high"},{"seq":12541,"id":"CVE-2026-63376","ts":1788944461516,"field":"cvss","old":"8.2","new":"3.7"},{"seq":12540,"id":"CVE-2026-63376","ts":1788944461516,"field":"severity","old":"high","new":"low"},{"seq":12131,"id":"CVE-2026-63376","ts":1788942755055,"field":"cvss","old":"3.7","new":"8.2"},{"seq":12130,"id":"CVE-2026-63376","ts":1788942755055,"field":"severity","old":"low","new":"high"}]}