GHSA-866w-xmhq-wj7xMedium· 4.3▾ SunlitSvelteKit: Prototype pollution in file input deletion path in remote-function forms
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
If you use remote form functions, have an input field of type file, and accept arbitrary user-controlled path names for the field, then you are vulnerable to a prototype pollution attack where the attacker can remove e.g. methods on the prototype.
@sveltejs/kit <= 2.69.0Upgrade to a patched release:
@sveltejs/kit 2.69.1Connected by shared product, vendor, weakness, or advisory.
GHSA-wqjv-9729-c5q2Medium· 5.3SvelteKit: Big remote form function payloads can cause Node process to crash
CVE-2026-66062Medium· 5.3SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte
CVE-2026-57439Medium· 5.0CyberChef: Prototype pollution in Series Chart operation
CVE-2026-92708High· 7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job
CVE-2026-81176Medium· 5.3Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job
CVE-2026-61534Critical· 9.1Yayson is a library for serializing and reading JSON API data in JavaScript