CVE-2026-82404: TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote through the obj...

Added to the CISA Known Exploited Vulnerabilities catalog on 02 Sep 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.3.

TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote through the object prototype chain instead of creating an own property, polluting Object.prototype for the runtime....

Required action: Review and patch if applicable to your AI infrastructure.