Overview
About vulnerability
If you use remote form functions, have an input field of typefile, and accept arbitrary user-controlled path names for the field, then you are vulnerable to a prototype pollution attack where the attacker can remove e.g. methods on the prototype.
Details
- Affected product:
- kit
- Affected packages:
- @sveltejs/kit @ 2.61.1