SvelteKit 在 2.69.1 版本之前存在原型污染漏洞,影响接受任意用户可控路径名称的远程表单函数中的文件输入字段。攻击者可以通过操纵删除路径来移除原型上的方法,从而潜在地禁用应用程序的部分功能。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82259 | 7.5 HIGH | SvelteKit 2.49.0 before 2.53.3 Denial of Service via form |
| CVE-2026-82260 | 7.5 HIGH | SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization |
| CVE-2026-82261 | 7.5 HIGH | SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserialization |
| CVE-2026-82258 | 5.9 MEDIUM | SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch |
| CVE-2026-82256 | 5.3 MEDIUM | SvelteKit before 2.69.1 Denial of Service via Remote Form |
No comments yet