← Voltar à pesquisa de CVEs

CVE-2026-82257

SvelteKit

Descrição

SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling application functionality.

CVSS 4.3EPSS 0%Risco 0.43
Ver fonte
Publicação
2026-08-28 12:16:38
Versões afetadas
<2.69.1
Tipo
Biblioteca
Última alteração
2026-08-28 16:18:33
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L