Логотип exploitDog
bind:CVE-2025-62381
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-62381

Количество 2

Количество 2

nvd логотип

CVE-2025-62381

4 месяца назад

sveltekit-superforms makes SvelteKit forms a pleasure to use. sveltekit-superforms v2.27.3 and prior are susceptible to a prototype pollution vulnerability within the parseFormData function of formData.js. An attacker can inject string and array properties into Object.prototype, leading to denial of service, type confusion, and potential remote code execution in downstream applications that rely on polluted objects. This vulnerability is fixed in 2.27.4.

EPSS: Низкий
github логотип

GHSA-hwmc-4c8j-xxj7

4 месяца назад

`sveltekit-superforms` has Prototype Pollution in `parseFormData` function of `formData.js`

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-62381

sveltekit-superforms makes SvelteKit forms a pleasure to use. sveltekit-superforms v2.27.3 and prior are susceptible to a prototype pollution vulnerability within the parseFormData function of formData.js. An attacker can inject string and array properties into Object.prototype, leading to denial of service, type confusion, and potential remote code execution in downstream applications that rely on polluted objects. This vulnerability is fixed in 2.27.4.

1%
Низкий
4 месяца назад
github логотип
GHSA-hwmc-4c8j-xxj7

`sveltekit-superforms` has Prototype Pollution in `parseFormData` function of `formData.js`

1%
Низкий
4 месяца назад

Уязвимостей на страницу