PT-2026-83109 · Sveltekit · Sveltekit
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SvelteKit versions prior to 2.69.1
Description
Remote form functions with file input fields that accept arbitrary user-controlled path names are susceptible to prototype pollution. This occurs when an attacker manipulates the deletion path to remove methods on the prototype, which can lead to the disabling of application functionality. Prototype pollution is a technique where an attacker modifies the base prototype of an object, affecting all objects derived from it.
Recommendations
Update to version 2.69.1 or later.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sveltekit