mediumCVSS 4.3Vulnerability
GHSA-866w-xmhq-wj7x
If you use remote form functions, have an input field of type `file`, and accept arbitrary user-controlled path names for the field, then you are vulnerable to a prototype pollution attack where the attacker can remove e.g. methods on the prototype.
Properties
- ghsa_id
- GHSA-866w-xmhq-wj7x
- severity
- medium
- summary
- SvelteKit: Prototype pollution in file input deletion path in remote-function forms
- cvss_score
- 4.3
- cve_id
- GHSA-866w-xmhq-wj7x
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
- is_ghsa_only
- true
- ghsa_published
- 2026-07-24T15:58:05Z
- source_url
- https://github.com/advisories/GHSA-866w-xmhq-wj7x
- ghsa_updated
- 2026-07-24T15:58:07Z
Related Entities (4)
HAS_WEAKNESS (1)
→[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]npm/@sveltejs/kit
AFFECTS (1)
→[Software]npm/@sveltejs/kit
Explore deeper with Ninja Signal's threat intelligence graph