CVE-2026-82257

SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling application functionality.
Configurations

Configuration 1 (hide)

cpe:2.3:a:svelte:sveltekit:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-08-28 12:16

Updated : 2026-08-31 16:43


NVD link : CVE-2026-82257

Mitre link : CVE-2026-82257

CVE.ORG link : CVE-2026-82257


JSON object : View

Products Affected

svelte

  • sveltekit
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')