{"id":"GHSA-4q55-j62x-fr9h","title":"devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion","summary":"devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion","severity":"medium","cwe":["CWE-1321"],"vendor":"devalue","product":"devalue","ecosystem":"npm","affected":["devalue <= 5.9.2"],"patched":["devalue 5.9.3"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:13:25Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-4q55-j62x-fr9h","references":[{"url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-4q55-j62x-fr9h"},{"url":"https://github.com/sveltejs/devalue/commit/9ec513072e31f45e60d44dad6f0dba9c92bb8675"},{"url":"https://github.com/sveltejs/devalue/releases/tag/v5.9.3"},{"url":"https://github.com/advisories/GHSA-4q55-j62x-fr9h"}],"tags":["ghsa","npm"],"ingestedAt":"2026-10-01T15:48:17.831Z","slug":"GHSA-4q55-j62x-fr9h","body":"## Overview\n\nThis is another instance of https://github.com/sveltejs/devalue/security/advisories/GHSA-mwv9-gp5h-frr4, where some payloads could cause `parse` to create objects with a `__proto__` own property. This on its own is not enough to cause prototype pollution, and indeed this is actually how `JSON.parse` works, but we decided to be a little more defensive here and not allow the creation of objects with `__proto__` own-properties. It is very unlikely for this to cause any issues.\n\n## Affected packages\n\n- `devalue <= 5.9.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `devalue 5.9.3`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}