GHSA-4q55-j62x-fr9hMedium▾ Sunlitdevalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This is another instance of https://github.com/sveltejs/devalue/security/advisories/GHSA-mwv9-gp5h-frr4, where some payloads could cause parse to create objects with a __proto__ own property. This on its own is not enough to cause prototype pollution, and indeed this is actually how JSON.parse works, but we decided to be a little more defensive here and not allow the creation of objects with __proto__ own-properties. It is very unlikely for this to cause any issues.
devalue <= 5.9.2Upgrade to a patched release:
devalue 5.9.3Connected by shared product, vendor, weakness, or advisory.
GHSA-x5rw-q4pp-hg5gHighdevalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
GHSA-hx4r-w6wj-j8fgMediumdevalue: Residual sparse-array CPU amplification in uneval
GHSA-mcm9-63f2-9j32Highdevalue: Repeated primitive strings cause quadratic expansion in uneval
GHSA-wf3x-273g-mvxvLowdevalue: Sparse arrays emitted by uneval cause eager allocation when evaluated
CVE-2026-92708High· 7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job
CVE-2026-81176Medium· 5.3Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job