VYPR
Medium severity4.3NVD Advisory· Published Aug 28, 2026

CVE-2026-82257

CVE-2026-82257

Description

SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling application functionality.

Affected products

2
  • Sveltejs/Kitinferred2 versions
    <2.69.1+ 1 more
    • (no CPE)range: <2.69.1
    • (no CPE)range: <2.69.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.