GHSA-866w-xmhq-wj7x

Updated on 24 Jul 2026

Severity

4.3 Medium severity

Details

CVSS score
4.3

Overview

About vulnerability

If you use remote form functions, have an input field of type file, and accept arbitrary user-controlled path names for the field, then you are vulnerable to a prototype pollution attack where the attacker can remove e.g. methods on the prototype.

Details

Affected product:
kit
Affected packages:
@sveltejs/kit @ 2.61.1