@sveltejs/kit
npm17 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @sveltejs/kitpage 1 of 1
- CVE-2023-29003HIGHCVSS 8.8EG 8.8✓ Fixed in 1.15.12023-04-04
SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit pro…
- CVE-2023-29008HIGHCVSS 8.8EG 8.8✓ Fixed in 1.15.22023-04-06
The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request fo…
- CVE-2024-23641HIGHCVSS 7.5EG 7.5✓ Fixed in 2.4.32024-01-24
SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/hosted sveltekit app throws `Request with GET/HEAD method cannot have body.` and crashes the preview/hosting. After this…
- CVE-2024-53261MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.8.32024-11-25
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input from *the request URL* flows into `end`, where it is used to render an HTML page returned to the user. This may result in …
- CVE-2024-53262MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.8.32024-11-25
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html template for errors contains placeholders that are replaced without escaping the content first. error.html is the page …
- CVE-2025-32388MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.20.62025-04-15
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.20.6 , unsanitized search param names cause XSS vulnerability. You are affected if you iterate over all entries of event.url.searc…
- CVE-2025-67647CRITICALCVSS 9.1EG 9.1✓ Fixed in 2.49.52026-01-15
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a server side request forgery (SSRF) and denial of service (DoS) under certain conditions. From 2…
- CVE-2026-22803HIGHCVSS 7.5EG 7.5✓ Fixed in 2.49.52026-01-15
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4, the experimental form remote function uses a binary data format containing a representation of submitted form data. A …
- CVE-2026-40073HIGHCVSS 7.5EG 7.5✓ Fixed in 2.57.12026-04-10
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under certain circumstances, requests could bypass the BODY_SIZE_LIMIT on SvelteKit applications running with adapter-node. …
- CVE-2026-40074HIGHCVSS 7.5EG 7.5✓ Fixed in 2.57.12026-04-10
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, redirect, when called from inside the handle server hook with a location parameter containing characters that are invalid in…
- CVE-2026-66062MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.70.22026-08-07
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the content negotiation header parser used by SvelteKit's request handling (for headers such as Accept) uses a regular expre…
- CVE-2026-82256MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.69.12026-08-28
SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the applic…
- CVE-2026-82257MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.69.12026-08-28
SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on …
- CVE-2026-82258MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2.60.12026-08-28
SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing conditions to access s…
- CVE-2026-82259HIGHCVSS 7.5EG 7.5✓ Fixed in 2.53.32026-08-28
SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to proc…
- CVE-2026-82260HIGHCVSS 7.5EG 7.5✓ Fixed in 2.52.22026-08-28
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can c…
- CVE-2026-82261HIGHCVSS 7.5EG 7.5✓ Fixed in 2.52.22026-08-28
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send malformed form data to cause the server to be…
Check whether @sveltejs/kit is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @sveltejs/kit CVEs against the assets you own.
Start Free Scan →