mediumCVSS 4.3Vulnerability

GHSA-866w-xmhq-wj7x

If you use remote form functions, have an input field of type `file`, and accept arbitrary user-controlled path names for the field, then you are vulnerable to a prototype pollution attack where the attacker can remove e.g. methods on the prototype.

Properties

ghsa_id
GHSA-866w-xmhq-wj7x
severity
medium
summary
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
cvss_score
4.3
cve_id
GHSA-866w-xmhq-wj7x
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
is_ghsa_only
true
ghsa_published
2026-07-24T15:58:05Z
source_url
https://github.com/advisories/GHSA-866w-xmhq-wj7x
ghsa_updated
2026-07-24T15:58:07Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/@sveltejs/kit

AFFECTS (1)

[Software]npm/@sveltejs/kit

Explore deeper with Ninja Signal's threat intelligence graph