Prototype Pollution in Svelte's Devalue Utility Library
CVE-2025-57820
7.9HIGH
What is CVE-2025-57820?
The devalue utility library prior to version 5.3.2 is susceptible to a vulnerability where a string passed to devalue.parse could create objects with overridden properties. This flaw stems from inadequate validation of the proto property and could lead to prototype pollution, potentially compromising the integrity of the application. Users are strongly advised to upgrade to version 5.3.2 or later to mitigate this security issue.
Affected Version(s)
devalue < 5.3.2