Input validation error in devalue - #VU151493
Published: September 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to create objects with a __proto__ own property.
The vulnerability exists due to improper handling of property-key coercion in the parse function when parsing malformed serialized payloads. A remote attacker can supply a malformed serialized payload to create objects with a __proto__ own property.