A AegiFlow
MEDIUMCVSS 4.3

GHSA-866w-xmhq-wj7x

SvelteKit: Prototype pollution in file input deletion path in remote-function forms

Published
2026-07-24
Modified
2026-07-24
Sources
github-advisory

Summary

If you use remote form functions, have an input field of type `file`, and accept arbitrary user-controlled path names for the field, then you are vulnerable to a prototype pollution attack where the attacker can remove e.g. methods on the prototype.

Affected packages

EcosystemPackageAffected versionsFixed versions
npm@sveltejs/kit2.69.1

Remediation: Upgrade to 2.69.1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.