PT-2026-24756 · Git+3 · Devalue

Jviide

·

Publicado

2026-03-11

·

Atualizado

2026-03-12

·

CVE-2026-30226

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Svelte devalue versions prior to 5.6.4
Description Svelte devalue is a JavaScript library used for serializing values into strings when JSON.stringify is insufficient. Versions 5.6.3 and earlier of devalue.parse and devalue.unflatten are susceptible to prototype pollution through maliciously crafted payloads. Successful exploitation could result in Denial of Service (DoS) or type confusion.
Recommendations Update to version 5.6.4 or later.

Exploit

Correção

Prototype Pollution

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-30226
GHSA-CFW5-2VXH-HR84

Produtos afetados

Devalue