PT-2026-24756 · Git+3 · Devalue
Jviide
·
Publicado
2026-03-11
·
Atualizado
2026-03-12
·
CVE-2026-30226
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Svelte devalue versions prior to 5.6.4
Description
Svelte devalue is a JavaScript library used for serializing values into strings when JSON.stringify is insufficient. Versions 5.6.3 and earlier of
devalue.parse and devalue.unflatten are susceptible to prototype pollution through maliciously crafted payloads. Successful exploitation could result in Denial of Service (DoS) or type confusion.Recommendations
Update to version 5.6.4 or later.
Exploit
Correção
Prototype Pollution
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Devalue