Executive brief
devalue is a JavaScript library that serializes and deserializes values. A flaw in how it rejects dangerous property keys allows crafted payloads to bypass protections against creating objects with a __proto__ own property. While this alone does not enable prototype pollution attacks, it weakens the library's defensive posture against this class of vulnerability.
Technical details
The parse and unflatten functions failed to reject non-string keys in null-prototype objects, allowing property-key coercion to bypass __proto__ rejection checks. An attacker can send a malformed serialized value to create objects with __proto__ as an own property, though this does not directly cause prototype pollution since JSON.parse exhibits the same behavior. The fix restricts non-string null-prototype object keys in both parse and unflatten functions.
Affected products
- Svelte devalue <= 5.9.2
Timeline
- 2026-10-01: disclosed
- 2026-10-01: patched: version 5.9.3