---
id: GHSA-4q55-j62x-fr9h
title: >-
  devalue: Malformed null-prototype object keys bypass __proto__ rejection via
  property-key coercion
summary: >-
  devalue: Malformed null-prototype object keys bypass __proto__ rejection via
  property-key coercion
severity: medium
cwe:
  - CWE-1321
vendor: devalue
product: devalue
ecosystem: npm
affected:
  - devalue <= 5.9.2
patched:
  - devalue 5.9.3
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:13:25Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-4q55-j62x-fr9h'
references:
  - url: >-
      https://github.com/sveltejs/devalue/security/advisories/GHSA-4q55-j62x-fr9h
  - url: >-
      https://github.com/sveltejs/devalue/commit/9ec513072e31f45e60d44dad6f0dba9c92bb8675
  - url: 'https://github.com/sveltejs/devalue/releases/tag/v5.9.3'
  - url: 'https://github.com/advisories/GHSA-4q55-j62x-fr9h'
tags:
  - ghsa
  - npm
ingestedAt: '2026-10-01T15:48:17.831Z'
---

## Overview

This is another instance of https://github.com/sveltejs/devalue/security/advisories/GHSA-mwv9-gp5h-frr4, where some payloads could cause `parse` to create objects with a `__proto__` own property. This on its own is not enough to cause prototype pollution, and indeed this is actually how `JSON.parse` works, but we decided to be a little more defensive here and not allow the creation of objects with `__proto__` own-properties. It is very unlikely for this to cause any issues.

## Affected packages

- `devalue <= 5.9.2`

## Remediation

Upgrade to a patched release:

- `devalue 5.9.3`
