Vulnerabilities/

Valibot: record() issue paths can make flatten() throw for inherited Object property names

Severity:
Medium

Description

valibot 1.4.1 can throw a TypeError inside its flatten() helper when validation issues contain attacker-controlled object keys such as toString, valueOf, or hasOwnProperty.

The issue is reachable through normal record() validation.

Recommendation

Update the valibot package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
valibot
Anything's wrong? Let us know Last updated on July 24, 2026