Junglewise Threat Intelligence

devalue library __proto__ bypass via malformed null-prototype keys

Severity: medium · CVSS 4 · Published 2026-10-01

Technologies: devalue (npm), Svelte Devalue. Vendors: npm, Svelte.

Executive brief

devalue is a JavaScript library that serializes and deserializes values. A flaw in how it rejects dangerous property keys allows crafted payloads to bypass protections against creating objects with a __proto__ own property. While this alone does not enable prototype pollution attacks, it weakens the library's defensive posture against this class of vulnerability.

Technical details

The parse and unflatten functions failed to reject non-string keys in null-prototype objects, allowing property-key coercion to bypass __proto__ rejection checks. An attacker can send a malformed serialized value to create objects with __proto__ as an own property, though this does not directly cause prototype pollution since JSON.parse exhibits the same behavior. The fix restricts non-string null-prototype object keys in both parse and unflatten functions.

Affected products

  • Svelte devalue <= 5.9.2

Timeline

  • 2026-10-01: disclosed
  • 2026-10-01: patched: version 5.9.3

References

Related threats