SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling application functionality.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 28 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling application functionality. | |
| Title | SvelteKit before 2.69.1 Prototype Pollution via File Input | |
| First Time appeared |
Svelte
Svelte kit |
|
| Weaknesses | CWE-1321 | |
| CPEs | cpe:2.3:a:svelte:kit:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Svelte
Svelte kit |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T10:49:41.355Z
Reserved: 2026-08-28T10:39:30.356Z
Link: CVE-2026-82257
No data.
Status : Received
Published: 2026-08-28T12:16:38.607
Modified: 2026-08-28T12:16:38.607
Link: CVE-2026-82257
No data.
OpenCVE Enrichment
No data.
Weaknesses