PT-2026-24756 · Git+3 · Devalue

Jviide

·

Published

2026-03-11

·

Updated

2026-03-12

·

CVE-2026-30226

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Svelte devalue versions prior to 5.6.4
Description Svelte devalue is a JavaScript library used for serializing values into strings when JSON.stringify is insufficient. Versions 5.6.3 and earlier of devalue.parse and devalue.unflatten are susceptible to prototype pollution through maliciously crafted payloads. Successful exploitation could result in Denial of Service (DoS) or type confusion.
Recommendations Update to version 5.6.4 or later.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2026-30226
GHSA-CFW5-2VXH-HR84

Affected Products

Devalue