PT-2026-83109 · Sveltekit · Sveltekit

·

CVE-2026-82257

·

Published

2026-07-24

·

Updated

2026-08-28

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SvelteKit versions prior to 2.69.1
Description Remote form functions with file input fields that accept arbitrary user-controlled path names are susceptible to prototype pollution. This occurs when an attacker manipulates the deletion path to remove methods on the prototype, which can lead to the disabling of application functionality. Prototype pollution is a technique where an attacker modifies the base prototype of an object, affecting all objects derived from it.
Recommendations Update to version 2.69.1 or later.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82257
GHSA-866W-XMHQ-WJ7X

Affected Products

Sveltekit