MEDIUM🇬🇧 English

CVE-2026-82257

CVSS 5.3v4.0pub. 2026-08-28upd. 2026-08-31

SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling application functionality.

oryginał EN
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Svelte Sveltekit

    APP
    Svelte
    < 2.69.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-82259HIGH8.7ten sam produkt

SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in t...

CVE-2026-82261HIGH8.7ten sam produkt

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled c...

CVE-2026-82260HIGH8.7ten sam produkt

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remo...

CVE-2023-29008HIGH8.8ten sam produkt

The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+s...

CVE-2023-29003HIGH8.8ten sam produkt

SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple...

CVE-2026-82257 — MEDIUM 5.3 | CVEbaza.pl