Prototype Pollution Vulnerability in SvelteKit by Svelte
CVE-2026-82257

5.3MEDIUM

Key Information:

Vendor

Sveltejs

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-82257?

SvelteKit versions prior to 2.69.1 are vulnerable to a prototype pollution issue stemming from remote form functions utilizing file input fields. The flaw allows malicious actors to exploit arbitrary user-controlled path names, potentially setting paths that may delete critical methods on the prototype. This manipulation can result in significant disruptions to application functionality and security, making it imperative for users to upgrade to the latest version to mitigate these risks.

Affected Version(s)

kit 0 < 2.69.1

kit 2.69.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iaohkut-from-NightWolf-Team
dummdidumm
.