Vulnerabilities/

Prototype pollution in swiper - swiper

Severity:
High

Description

A prototype pollution vulnerability exists in the the npm package swiper (>=6.5.1, < 12.1.2). Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using Array.prototype.

Recommendation

Update the swiper package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
swiper
Anything's wrong? Let us know Last updated on February 23, 2026