{"id":"GHSA-8qm3-746x-r74r","aliases":[],"url":"https://o3.security/vulnerability/GHSA-8qm3-746x-r74r","summary":"devalue `uneval`ed code can create objects with polluted prototypes when `eval`ed","details":"Under certain circumstances, `uneval`ing untrusted data can produce output code that will create objects with polluted prototypes when later `eval`ed, meaning the output data can be a different shape from the input data.","published":"2026-02-19T20:29:17Z","modified":"2026-02-22T23:43:48.066457Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"devalue","fixedVersion":"5.6.3"}],"fix":{"url":"https://github.com/sveltejs/devalue/commit/0f04d4d678eac39ad5d7a07d1956275d7874e81c","label":"sveltejs/devalue@0f04d4d"},"references":[{"type":"WEB","url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-8qm3-746x-r74r"},{"type":"WEB","url":"https://github.com/sveltejs/devalue/commit/0f04d4d678eac39ad5d7a07d1956275d7874e81c"},{"type":"PACKAGE","url":"https://github.com/sveltejs/devalue"},{"type":"WEB","url":"https://github.com/sveltejs/devalue/releases/tag/v5.6.3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-22T23:43:48.066457Z"}}