{"id":"GHSA-cfw5-2vxh-hr84","summary":"devalue has prototype pollution in devalue.parse and devalue.unflatten","details":"In devalue v5.6.3, `devalue.parse` and `devalue.unflatten` were susceptible to prototype pollution via maliciously crafted payloads. Successful exploitation could lead to Denial of Service (DoS) or type confusion.","aliases":["CVE-2026-30226"],"modified":"2026-03-12T14:42:40.667023Z","published":"2026-03-12T14:13:03Z","database_specific":{"cwe_ids":["CWE-1321"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-12T14:13:03Z","nvd_published_at":"2026-03-11T18:16:22Z"},"references":[{"type":"WEB","url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-cfw5-2vxh-hr84"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30226"},{"type":"PACKAGE","url":"https://github.com/sveltejs/devalue"}],"affected":[{"package":{"name":"devalue","ecosystem":"npm","purl":"pkg:npm/devalue"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.6.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-cfw5-2vxh-hr84/GHSA-cfw5-2vxh-hr84.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}