Description
If you use remote form functions, have an input field of type file, and accept arbitrary user-controlled path names for the field, then you are vulnerable to a prototype pollution attack where the attacker can remove e.g. methods on the prototype.
Recommendation
Update the @sveltejs/kit package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.69.0
- Patched version(s): 2.69.1
References
Could your website be exposed too?
SmartScanner can check your website for SvelteKit: Prototype pollution in file input deletion path in remote-function forms and gives you actionable findings to investigate.
Start a free scanRelated Issues
- SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimenta - Vulnerability
- SvelteKit: Big remote form function payloads can cause Node process to crash - Vulnerability
- Prototype pollution in emit function - Vulnerability
- Velocity.js has a Prototype Pollution vulnerability through #set path assignment - CVE-2026-44966


