{"id":"CVE-2026-82257","aliases":["GHSA-866w-xmhq-wj7x"],"url":"https://o3.security/vulnerability/CVE-2026-82257","summary":"SvelteKit before 2.69.1 Prototype Pollution via File Input","details":"SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling application functionality.","published":"2026-08-28T10:49:41.355Z","modified":"2026-09-02T03:47:22.797309146Z","cvss":null,"epss":{"score":0.00205,"percentile":0.10576,"asOf":"2026-09-06"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@sveltejs/kit","fixedVersion":"2.69.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82257.json"},{"type":"ADVISORY","url":"https://github.com/sveltejs/kit/security/advisories/GHSA-866w-xmhq-wj7x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82257"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/sveltekit-before-2.69.1-prototype-pollution-via-file-input"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-02T03:47:22.797309146Z"}}