MEDIUM 5.3 NVD
CVE-2026-82257
SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controll
SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling application functionality.
References
- https://github.com/sveltejs/kit/security/advisories/GHSA-866w-xmhq-wj7x
- https://www.vulncheck.com/advisories/sveltekit-before-2.69.1-prototype-pollution-via-file-
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-08-28 via NVD.
vulnfeed aggregates 11493 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.