CVE-2026-82257: SvelteKit before 2.69.1 Prototype Pollution via File Input
SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling application functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SvelteKitto a version that resolves this vulnerability.Fixed in 2.69.1
Event History
Frequently Asked Questions
Which applications are exposed?
Applications using SvelteKit versions before 2.69.1 are affected when they use remote form functions with file input fields that accept arbitrary user-controlled path names.
What does an attacker need to exploit this issue?
An attacker needs to manipulate the deletion path associated with a susceptible file input. The supplied severity vector indicates network access is possible without privileges, but user interaction is required.
What remediation version is identified?
Update SvelteKit to version 2.69.1 or later. The issue affects versions before 2.69.1.