SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling application functionality.
References
| Link | Resource |
|---|---|
| https://github.com/sveltejs/kit/security/advisories/GHSA-866w-xmhq-wj7x | Vendor Advisory |
| https://www.vulncheck.com/advisories/sveltekit-before-2.69.1-prototype-pollution-via-file-input | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-28 12:16
Updated : 2026-08-31 16:43
NVD link : CVE-2026-82257
Mitre link : CVE-2026-82257
CVE.ORG link : CVE-2026-82257
JSON object : View
Products Affected
svelte
- sveltekit
CWE
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
