PT-2026-24756 · Git+3 · Devalue
Jviide
·
Published
2026-03-11
·
Updated
2026-03-12
·
CVE-2026-30226
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Svelte devalue versions prior to 5.6.4
Description
Svelte devalue is a JavaScript library used for serializing values into strings when JSON.stringify is insufficient. Versions 5.6.3 and earlier of
devalue.parse and devalue.unflatten are susceptible to prototype pollution through maliciously crafted payloads. Successful exploitation could result in Denial of Service (DoS) or type confusion.Recommendations
Update to version 5.6.4 or later.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Devalue