Executive brief
SvelteKit is a popular framework for building web applications. A vulnerability exists where an attacker can manipulate the internal structure of the application's memory by submitting specially crafted file upload forms. This could allow an attacker to crash the application or interfere with its normal operation by deleting essential internal functions.
Technical details
A prototype pollution vulnerability (CWE-1321) exists in @sveltejs/kit within the file input deletion path of remote-function forms. When an application uses remote form functions and accepts arbitrary user-controlled path names for a 'file' type input field, an attacker can craft a request to modify or delete attributes on the Object prototype. This is achieved by providing malicious path names that traverse to the prototype. The vulnerability is exploitable via the network with user interaction, potentially leading to a denial of service by removing critical prototype methods. The issue is fixed in version 2.69.1 and 3.0.0-next.7.
Affected products
- SvelteKit @sveltejs/kit <= 2.69.0
Timeline
- 2026-07-02: disclosed: Initial disclosure to developers
- 2026-07-24: advisory: GitHub Advisory published
- 2026-07-24: patched: Fix released in version 2.69.1
References
- https://api.github.com/users/alanturing881
- https://github.com/alanturing881
- https://api.github.com/users/alanturing881/gists%7B/gist_id%7D
- https://api.github.com/users/alanturing881/repos
- https://avatars.githubusercontent.com/u/286391906?v=4
- https://api.github.com/users/alanturing881/events%7B/privacy%7D