Executive brief
devalue is a JavaScript library used to safely serialize and deserialize data. A parsing flaw allows malformed null-prototype objects to bypass security checks that prevent creating objects with __proto__ properties, which the library intentionally blocks to avoid prototype pollution attacks. While unlikely to cause issues, this reduces the defensive stance against potential object manipulation.
Technical details
The parse function in devalue can be bypassed via property-key coercion in certain payloads involving null-prototype objects, allowing __proto__ to be set as an own property despite defensive filtering. This follows a similar vulnerability (GHSA-mwv9-gp5h-frr4) and requires sending malformed serialized data to the parse function over a network or through user-supplied input. While the authors note this mirrors normal JSON.parse behavior and is unlikely to cause harm, it circumvents their intentional restrictions.
Affected products
- Svelte devalue <= 5.9.2
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched: Version 5.9.3 released
- 2026-10-01: advisory: Published to GitHub Advisory Database