PT-2026-96973 · Npm · Js-Toml

CVE-2026-63386

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions js-toml versions prior to 1.1.3
Description The load() function fails to limit nesting or dotted-key depth within the recursive parser at src/load/parser.ts and the interpreter at src/load/interpreter.ts. Consequently, processing deeply nested arrays, deeply nested inline tables, or long dotted keys can exhaust the V8 call stack, triggering a raw RangeError instead of the expected SyntaxParseError. If an application parses attacker-controlled TOML and only handles SyntaxParseError, the unexpected exception can cause a worker or process to terminate, leading to a denial of service. This synchronous exception can be caught by consumers handling all exceptions and does not impact confidentiality or integrity.
Recommendations Update to version 1.1.3.

Exploit

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63386
GHSA-3G82-77XR-68X5

Affected Products

Js-Toml