Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23575 | js-toml Prototype Pollution Vulnerability |
Github GHSA |
GHSA-65fc-cr5f-v7r2 | js-toml Prototype Pollution Vulnerability |
Thu, 09 Oct 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:sunnyadn:js-toml:*:*:*:*:*:node.js:*:* | |
| Metrics |
cvssV3_1
|
Tue, 05 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sunnyadn
Sunnyadn js-toml |
|
| Vendors & Products |
Sunnyadn
Sunnyadn js-toml |
Tue, 05 Aug 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype pollution vulnerability in js-toml allows a remote attacker to add or modify properties of the global Object.prototype by parsing a maliciously crafted TOML input. This is fixed in version 1.0.2. | |
| Title | js-toml is vulnerable to Prototype Pollution | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-05T14:31:35.284Z
Reserved: 2025-07-29T16:50:28.395Z
Link: CVE-2025-54803
Updated: 2025-08-05T14:31:31.744Z
Status : Analyzed
Published: 2025-08-05T01:15:42.400
Modified: 2025-10-09T17:32:53.573
Link: CVE-2025-54803
No data.
OpenCVE Enrichment
Updated: 2025-08-05T11:38:48Z
EUVD
Github GHSA