All 3 CVE vulnerabilities found in js-toml, with AI-generated Chinese analysis, references, and POCs.
Vendor: sunnyadn
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-50029 | js-toml has silent type confusion via falsy-primitive duplicate-key bypass CWE-697 | 5.3 | Medium | 2026-08-14 |
| CVE-2026-49293 | CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals CWE-400 | 7.5 | High | 2026-06-19 |
| CVE-2025-54803 | js-toml is vulnerable to Prototype Pollution CWE-1321 | 9.8AI | Critical AI | 2025-08-05 |
All 3 known CVE vulnerabilities affecting js-toml with full Chinese analysis, references, and POCs where available.