mediumVulnerability

GHSA-4q55-j62x-fr9h

This is another instance of https://github.com/sveltejs/devalue/security/advisories/GHSA-mwv9-gp5h-frr4, where some payloads could cause `parse` to create objects with a `__proto__` own property. This on its own is not enough to cause prototype pollution, and indeed this is actually how `JSON.parse` works, but we decided to be a little more defensive here and not allow the creation of objects with `__proto__` own-properties. It is very unlikely for this to cause any issues.

Properties

ghsa_id
GHSA-4q55-j62x-fr9h
severity
medium
summary
devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
last_source
GitHub Advisory Database
cve_id
GHSA-4q55-j62x-fr9h
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
true
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:13:23Z
source_url
https://github.com/advisories/GHSA-4q55-j62x-fr9h
ghsa_updated
2026-10-01T15:13:25Z

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/devalue

AFFECTS (1)

→[Software]npm/devalue

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-4q55-j62x-fr9h — Ninja Signal Threat Intelligence | Ninja Signal