Client-side validation is not a security boundary

Checks in the browser are a courtesy to the user. Whoever is attacking you is not using your browser.

They send the request directly, with whatever values they like, and every rule you enforced in JavaScript is absent. Client-side validation improves the experience and prevents mistakes. The server has to assume none of it happened.

More on Browser security