Prototype Pollution Vulnerability in Svelte Devalue JavaScript Library
CVE-2026-30226

6.3MEDIUM

Key Information:

Vendor

Sveltejs

Status
Vendor
CVE Published:
11 March 2026

What is CVE-2026-30226?

The Svelte Devalue JavaScript library, used for serializing values, is susceptible to prototype pollution vulnerabilities in versions v5.6.3 and earlier. Maliciously crafted payloads targeting the devalue.parse and devalue.unflatten methods could allow an attacker to manipulate object prototypes, resulting in Denial of Service (DoS) conditions or type confusion issues. This vulnerability has been addressed in version 5.6.4. It is crucial for users to update to the latest version to safeguard their applications.

Affected Version(s)

devalue < 5.6.4

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.