Vulnerability GHSA-4q55-j62x-fr9h

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 hours ago
October 01, 2026 at 03:13 PM UTC
devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
1.0.0 - 5.9.2
1.0.0 - 5.9.2

Summary

devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion

Details

This is another instance of https://github.com/sveltejs/devalue/security/advisories/GHSA-mwv9-gp5h-frr4, where some payloads could cause parse to create objects with a __proto__ own property. This on its own is not enough to cause prototype pollution, and indeed this is actually how JSON.parse works, but we decided to be a little more defensive here and not allow the creation of objects with __proto__ own-properties. It is very unlikely for this to cause any issues.

Impacted packages

Timeline

Published
2 hours ago
October 01, 2026 at 03:13 PM UTC
Fixed (5.9.3)
Unknown
Unknown
Last Modified
1 hour ago
October 01, 2026 at 03:30 PM UTC