Junglewise Threat Intelligence

devalue __proto__ rejection bypass via property-key coercion

Severity: medium · Published 2026-10-01

Technologies: devalue (npm), Svelte Devalue. Vendors: npm, Svelte.

Executive brief

devalue is a JavaScript library used to safely serialize and deserialize data. A parsing flaw allows malformed null-prototype objects to bypass security checks that prevent creating objects with __proto__ properties, which the library intentionally blocks to avoid prototype pollution attacks. While unlikely to cause issues, this reduces the defensive stance against potential object manipulation.

Technical details

The parse function in devalue can be bypassed via property-key coercion in certain payloads involving null-prototype objects, allowing __proto__ to be set as an own property despite defensive filtering. This follows a similar vulnerability (GHSA-mwv9-gp5h-frr4) and requires sending malformed serialized data to the parse function over a network or through user-supplied input. While the authors note this mirrors normal JSON.parse behavior and is unlikely to cause harm, it circumvents their intentional restrictions.

Affected products

  • Svelte devalue <= 5.9.2

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched: Version 5.9.3 released
  • 2026-10-01: advisory: Published to GitHub Advisory Database

References

Related threats