Skip to content

fix: 404 for form actions and remote functions whose name is an Object.prototype member - #16072

Merged
teemingc merged 2 commits into
version-3from
elliott/fix-15525-form-action-prototype-pollution
Jun 23, 2026
Merged

fix: 404 for form actions and remote functions whose name is an Object.prototype member#16072
teemingc merged 2 commits into
version-3from
elliott/fix-15525-form-action-prototype-pollution

Conversation

@elliott-with-the-longest-name-on-github

@elliott-with-the-longest-name-on-github elliott-with-the-longest-name-on-github commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Closes #15525.

Form action lookup used a plain truthiness check (actions[name]), so submitting ?/toString, ?/constructor, etc. resolved an inherited Object.prototype member and slipped past the "no such action" 404 guard (returning 200 or blowing up with a 500). Swapped that for an Object.hasOwn check so only actually-defined actions resolve.

While I was in there I noticed the remote-functions handler in remote.js has the same pattern — the remotes map and the function-name lookups are both derived from the request URL — so I hardened those with Object.hasOwn too.

@changeset-bot

changeset-bot Bot commented Jun 17, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: a812f7b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/kit Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@svelte-docs-bot

Copy link
Copy Markdown

@teemingc
teemingc merged commit dba6239 into version-3 Jun 23, 2026
31 of 33 checks passed
@teemingc
teemingc deleted the elliott/fix-15525-form-action-prototype-pollution branch June 23, 2026 13:42
Rich-Harris pushed a commit that referenced this pull request Jun 26, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to version-3, this PR
will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`version-3` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `version-3`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## @sveltejs/adapter-netlify@7.0.0-next.1

### Major Changes


- breaking: require `vite@^8.0.12`, the first Vite 8 release bundling
stable `rolldown` 1.0.0
([#16134](#16134))


### Patch Changes

- Updated dependencies
[[`a9629f1`](a9629f1),
[`53d37f9`](53d37f9),
[`dba6239`](dba6239),
[`ab12cb6`](ab12cb6),
[`f0eab52`](f0eab52),
[`cd884c1`](cd884c1),
[`9ed38a8`](9ed38a8),
[`53aa049`](53aa049),
[`984e57a`](984e57a),
[`51785be`](51785be),
[`4f6bcbb`](4f6bcbb),
[`78e7137`](78e7137)]:
  - @sveltejs/kit@3.0.0-next.5
## @sveltejs/adapter-node@6.0.0-next.1

### Major Changes


- breaking: require `vite@^8.0.12`, the first Vite 8 release bundling
stable `rolldown` 1.0.0
([#16134](#16134))


### Patch Changes

- Updated dependencies
[[`a9629f1`](a9629f1),
[`53d37f9`](53d37f9),
[`dba6239`](dba6239),
[`ab12cb6`](ab12cb6),
[`f0eab52`](f0eab52),
[`cd884c1`](cd884c1),
[`9ed38a8`](9ed38a8),
[`53aa049`](53aa049),
[`984e57a`](984e57a),
[`51785be`](51785be),
[`4f6bcbb`](4f6bcbb),
[`78e7137`](78e7137)]:
  - @sveltejs/kit@3.0.0-next.5
## @sveltejs/adapter-vercel@7.0.0-next.1

### Major Changes


- breaking: require `vite@^8.0.12`, the first Vite 8 release bundling
stable `rolldown` 1.0.0
([#16134](#16134))


### Patch Changes

- Updated dependencies
[[`a9629f1`](a9629f1),
[`53d37f9`](53d37f9),
[`dba6239`](dba6239),
[`ab12cb6`](ab12cb6),
[`f0eab52`](f0eab52),
[`cd884c1`](cd884c1),
[`9ed38a8`](9ed38a8),
[`53aa049`](53aa049),
[`984e57a`](984e57a),
[`51785be`](51785be),
[`4f6bcbb`](4f6bcbb),
[`78e7137`](78e7137)]:
  - @sveltejs/kit@3.0.0-next.5
## @sveltejs/enhanced-img@1.0.0-next.1

### Major Changes


- breaking: require `vite@^8.0.12`, the first Vite 8 release bundling
stable `rolldown` 1.0.0
([#16134](#16134))
## @sveltejs/kit@3.0.0-next.5

### Major Changes


- breaking: remove `base`, `assets`, and `resolveRoute` from
`$app/paths` ([#15507](#15507))


- breaking: require Svelte config options to be passed through the Vite
plugin ([#16007](#16007))


- breaking: `goto` now rejects when called with a URL that does not
resolve to a route within the app, matching the existing behaviour for
external URLs ([#16164](#16164))


- breaking: add 'error' result type to `preloadData`
([#12579](#12579))


- breaking: require `vite@^8.0.12`, the first Vite 8 release bundling
stable `rolldown` 1.0.0
([#16134](#16134))


### Minor Changes


- feat: expose `submitted` property of remote forms
([#14811](#14811))


### Patch Changes


- fix: clear issues and touched states on form reset
([#16163](#16163))


- fix: return 404 for form actions and remote functions whose name is an
`Object.prototype` member
([#16072](#16072))


- feat: send periodic `keep-alive` SSE comments from `query.live` to
prevent idle-timeout errors
([#16063](#16063))


- fix: render pages over sibling endpoints without GET or HEAD handlers
([#16125](#16125))


- fix: sort directory entries when building the route manifest so node
indices are deterministic across runtimes (e.g. Bun and Node)
([#16074](#16074))


- fix: include hoisted packages in Vite's `server.fs.allow` list
([#15998](#15998))
## @sveltejs/package@3.0.0-next.1

### Patch Changes


- fix: declare typescript as an optional peer dependency so
svelte-package works under strict node-linkers
([#16073](#16073))

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
teemingc added a commit that referenced this pull request Aug 3, 2026
a matcher named `toString` passed validation via the prototype chain and
blew up during matching. Same class as #16072.

---

### Please don't delete this checklist! Before submitting the PR, please
make sure you do the following:

- [x] It's really useful if your PR references an issue where it is
discussed ahead of time. In many cases, features are absent for a
reason. For large changes, please create an RFC:
https://github.com/sveltejs/rfcs
- [x] This message body should clearly illustrate what problems it
solves.
- [x] Ideally, include a test that fails without this PR but passes with
it.

### Tests

- [x] Run the tests with `pnpm test` and lint the project with `pnpm
lint` and `pnpm check`

### Changesets

- [x] If your PR makes a change that should be noted in one or more
packages' changelogs, generate a changeset by running `pnpm changeset`
and following the prompts. Changesets that add features should be
`minor` and those that fix bugs should be `patch`. Please prefix
changeset messages with `feat:`, `fix:`, or `chore:`.

### Edits

- [x] Please ensure that 'Allow edits from maintainers' is checked. PRs
without this option may be closed.

Co-authored-by: Tee Ming <chewteeming01@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Form action lookup resolves Object.prototype methods via bracket notation

2 participants