CVE-2025-62381: `sveltekit-superforms` has Prototype Pollution in `parseFormData` function of `formData.js`
sveltekit-superforms v2.27.3 and prior are susceptible to a prototype pollution vulnerability within the parseFormData function of formData.js. An attacker can inject string and array properties into Object.prototype, leading to denial of service, type confusion, and potential remote code execution in downstream applications that rely on polluted objects.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-62381 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →