{"id":"GHSA-mwv9-gp5h-frr4","summary":"Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own properties","details":"In some circumstances, `devalue.parse` and `devalue.unflatten` could emit objects with `__proto__` own properties. This in and of itself is not a security vulnerability (and is possible with, for example, `JSON.parse` as well), but it can result in prototype injection if _downstream_ code handles it incorrectly:\n\n```ts\nconst result = devalue.parse(/* input creating an object with a __proto__ property */);\nconst target = {};\nObject.assign(target, result); // target's prototype is now polluted\n```","modified":"2026-06-26T20:45:12.223841084Z","published":"2026-03-12T16:38:15Z","database_specific":{"github_reviewed_at":"2026-03-12T16:38:15Z","nvd_published_at":null,"cwe_ids":["CWE-1321"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-mwv9-gp5h-frr4"},{"type":"WEB","url":"https://github.com/sveltejs/devalue/commit/87c1f3ce3759765a061cfe34843ecc4b0711ba8d"},{"type":"PACKAGE","url":"https://github.com/sveltejs/devalue"},{"type":"WEB","url":"https://github.com/sveltejs/devalue/releases/tag/v5.6.4"}],"affected":[{"package":{"name":"devalue","ecosystem":"npm","purl":"pkg:npm/devalue"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"5.6.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mwv9-gp5h-frr4/GHSA-mwv9-gp5h-frr4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}]}