{"id":"CVE-2026-82257","title":"SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names","summary":"SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods o…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","cwe":["CWE-1321"],"vendor":"svelte","product":"sveltekit","affected":["sveltekit < 2.69.1"],"patched":["sveltekit 2.69.1"],"published":"2026-08-28","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:48.293","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82257","references":[{"url":"https://github.com/sveltejs/kit/security/advisories/GHSA-866w-xmhq-wj7x","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/sveltekit-before-2.69.1-prototype-pollution-via-file-input","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-28T13:58:20.486385Z"},"epss":0.00358,"epssPercentile":0.27427,"ingestedAt":"2026-10-08T16:52:14.733Z","slug":"CVE-2026-82257","body":"## Overview\n\nSvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling application functionality.\n\n## Affected\n\n- `sveltekit < 2.69.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `sveltekit 2.69.1`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}