Skip to content

pnpm audit: @sveltejs/kit pins vulnerable devalue 5.8.1 (GHSA-9rgm-9g3h-6x36) #107

Description

@shockalotti

What

pnpm audit in frontend/ reports 1 moderate: devalue <5.9.1 DoS via malformed input (GHSA-9rgm-9g3h-6x36), patched in >=5.9.2.

Where

  • frontend/pnpm-lock.yaml: @sveltejs/kit@2.70.3 depends on devalue: 5.8.1 (vulnerable). svelte@5.57.0 already uses devalue: 5.9.2 (patched).
  • @sveltejs/kit@2.70.3 is the latest upstream release, so no fixed Kit version exists yet. This is blocked on upstream.

Risk in this app: low

  • frontend/src uses no Kit remote functions and no direct devalue calls (checked). The attacker-reachable devalue.parse path (remote-function payloads) is not used here. Remaining use is server-serialize to client-parse of page data, which an attacker cannot supply.

Options

  1. Wait for upstream Kit to bump devalue, then pnpm update @sveltejs/kit. Preferred.
  2. Short-term pnpm.override pinning devalue@>=5.9.2. Only with full frontend test pass, since it overrides a serialization lib under Kit.

Found by the 0.10.1 pre-release audit (Layer 1). The clean-security-scan manifest claim covers the Go backend only, so this does not contradict it, but AUDIT.md tells operators to run pnpm audit and they will see this.

Activity

  1. pullfrog commented on Sep 29, 2026

    @pullfrog
    Contributor
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions