A vulnerability classified as critical has been found in open-circle valibot up to 1.4.1. The affected element is the function flatten. This manipulation causes improperly controlled modification of object prototype attributes.

This vulnerability is registered as CVE-2026-59952. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component.