MEDIUMCVSS 4.3
GHSA-866w-xmhq-wj7x
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
Summary
If you use remote form functions, have an input field of type `file`, and accept arbitrary user-controlled path names for the field, then you are vulnerable to a prototype pollution attack where the attacker can remove e.g. methods on the prototype.
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| npm | @sveltejs/kit | — | 2.69.1 |
Remediation: Upgrade to 2.69.1 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.