Improper Handling of Exceptional Conditions Affecting valibot package, versions <1.4.2


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.52% (42nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-VALIBOT-18313048
  • published26 Jul 2026
  • disclosed24 Jul 2026
  • creditFaze-up

Introduced: 24 Jul 2026

NewCVE-2026-59952  (opens in a new tab)
CWE-755  (opens in a new tab)

How to fix?

Upgrade valibot to version 1.4.2 or higher.

Overview

valibot is a The modular and type safe schema library for validating structural data

Affected versions of this package are vulnerable to Improper Handling of Exceptional Conditions in the flatten process. An attacker can cause the application to throw a TypeError and disrupt normal error handling by submitting specially crafted JSON objects containing keys that collide with inherited Object.prototype property names, such as toString, valueOf, or hasOwnProperty, which are then processed by the validation and error-flattening logic.

CVSS Base Scores

version 4.0
version 3.1