sveltekit-superforms is vulnerable to Prototype Pollution
70
High Risk
Affected versions of this package are vulnerable to prototype pollution when using dataType: 'json'. This vulnerability enables an attacker to inject malicious properties into object prototypes by crafting JSON input that includes __proto__, potentially leading to security issues, including remote code execution or denial of service. Before the fix, an attacker could exploit this by sending specially designed data that pollutes the prototype chain, potentially altering the behavior of all objects in the application and enabling further attacks.
You are affected if you are using a version that falls within the vulnerable range.
sveltekit-superforms is vulnerable to Prototype Pollution in versions 2.0.0 - 2.27.3.
Upgrade the sveltekit-superforms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant