pwnmyvibecode_

SvelteKit vulnerabilities and security advisories

The newest reviewed advisories for @sveltejs/kit and svelte on npm. Each one shows which versions are affected, which version fixes it, and a prompt that has your AI agent check your project and upgrade only if it needs to.

Get an email when SvelteKit has a new one

Email alerts are coming soon. This page updates every hour.

$ latest 30 · 7 critical, high or exploited

  • mediumAug 7, 2026

    SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header

    • @sveltejs/kit <= 2.70.1 · fixed in 2.70.2
    GHSA-29g2-3rmr-qm68CVE-2026-66062
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-29g2-3rmr-qm68 (CVE-2026-66062), severity medium
    What it is: SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
    Affected packages:
    - @sveltejs/kit: affected versions <= 2.70.1. Fixed in 2.70.2.
    Details: https://github.com/advisories/GHSA-29g2-3rmr-qm68
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJul 24, 2026

    SvelteKit: Prototype pollution in file input deletion path in remote-function forms

    • @sveltejs/kit <= 2.69.0 · fixed in 2.69.1
    GHSA-866w-xmhq-wj7x
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-866w-xmhq-wj7x, severity medium
    What it is: SvelteKit: Prototype pollution in file input deletion path in remote-function forms
    Affected packages:
    - @sveltejs/kit: affected versions <= 2.69.0. Fixed in 2.69.1.
    Details: https://github.com/advisories/GHSA-866w-xmhq-wj7x
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJul 24, 2026

    SvelteKit: Big remote form function payloads can cause Node process to crash

    • @sveltejs/kit <= 2.69.0 · fixed in 2.69.1
    GHSA-wqjv-9729-c5q2
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-wqjv-9729-c5q2, severity medium
    What it is: SvelteKit: Big remote form function payloads can cause Node process to crash
    Affected packages:
    - @sveltejs/kit: affected versions <= 2.69.0. Fixed in 2.69.1.
    Details: https://github.com/advisories/GHSA-wqjv-9729-c5q2
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 21, 2026

    @sveltejs/kit: `query.batch` cross-talk

    • @sveltejs/kit >= 2.38.0, <= 2.60.0 · fixed in 2.60.1
    GHSA-hgv7-v322-mmgr
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-hgv7-v322-mmgr, severity medium
    What it is: @sveltejs/kit: `query.batch` cross-talk
    Affected packages:
    - @sveltejs/kit: affected versions >= 2.38.0, <= 2.60.0. Fixed in 2.60.1.
    Details: https://github.com/advisories/GHSA-hgv7-v322-mmgr
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 14, 2026

    Svelte: SSR XSS via Insecure Promise Serialization in hydratable

    • svelte >= 5.46.0, <= 5.55.6 · fixed in 5.55.7
    GHSA-f3cj-j4f6-wq85
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-f3cj-j4f6-wq85, severity medium
    What it is: Svelte: SSR XSS via Insecure Promise Serialization in hydratable
    Affected packages:
    - svelte: affected versions >= 5.46.0, <= 5.55.6. Fixed in 5.55.7.
    Details: https://github.com/advisories/GHSA-f3cj-j4f6-wq85
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 14, 2026

    Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State

    • svelte <= 5.55.6 · fixed in 5.55.7
    GHSA-rcqx-6q8c-2c42CVE-2026-42573
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-rcqx-6q8c-2c42 (CVE-2026-42573), severity medium
    What it is: Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State
    Affected packages:
    - svelte: affected versions <= 5.55.6. Fixed in 5.55.7.
    Details: https://github.com/advisories/GHSA-rcqx-6q8c-2c42
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 14, 2026

    Svelte: ReDoS in `<svelte:element>` Tag Validation

    • svelte >= 5.51.5, <= 5.55.6 · fixed in 5.55.7
    GHSA-9rmh-mm8f-r9h6CVE-2026-42567
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-9rmh-mm8f-r9h6 (CVE-2026-42567), severity medium
    What it is: Svelte: ReDoS in `<svelte:element>` Tag Validation
    Affected packages:
    - svelte: affected versions >= 5.51.5, <= 5.55.6. Fixed in 5.55.7.
    Details: https://github.com/advisories/GHSA-9rmh-mm8f-r9h6
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 14, 2026

    Svelte SSR vulnerable to cross-site scripting via spread attributes

    • svelte <= 5.55.6 · fixed in 5.55.7
    GHSA-pr6f-5x2q-rwfpCVE-2026-42599
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-pr6f-5x2q-rwfp (CVE-2026-42599), severity medium
    What it is: Svelte SSR vulnerable to cross-site scripting via spread attributes
    Affected packages:
    - svelte: affected versions <= 5.55.6. Fixed in 5.55.7.
    Details: https://github.com/advisories/GHSA-pr6f-5x2q-rwfp
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumApr 10, 2026

    @sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service

    • @sveltejs/kit <= 2.57.0 · fixed in 2.57.1
    GHSA-3f6h-2hrp-w5wxCVE-2026-40074
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-3f6h-2hrp-w5wx (CVE-2026-40074), severity medium
    What it is: @sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
    Affected packages:
    - @sveltejs/kit: affected versions <= 2.57.0. Fixed in 2.57.1.
    Details: https://github.com/advisories/GHSA-3f6h-2hrp-w5wx
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highApr 10, 2026

    @sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass

    • @sveltejs/kit <= 2.57.0 · fixed in 2.57.1
    GHSA-2crg-3p73-43xpCVE-2026-40073
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-2crg-3p73-43xp (CVE-2026-40073), severity high
    What it is: @sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
    Affected packages:
    - @sveltejs/kit: affected versions <= 2.57.0. Fixed in 2.57.1.
    Details: https://github.com/advisories/GHSA-2crg-3p73-43xp
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • lowFeb 28, 2026

    SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)

    • @sveltejs/kit >= 2.49.0, <= 2.53.2 · fixed in 2.53.3
    GHSA-fpg4-jhqr-589c
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-fpg4-jhqr-589c, severity low
    What it is: SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
    Affected packages:
    - @sveltejs/kit: affected versions >= 2.49.0, <= 2.53.2. Fixed in 2.53.3.
    Details: https://github.com/advisories/GHSA-fpg4-jhqr-589c
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumFeb 26, 2026

    Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers

    • svelte >= 5.53.0, < 5.53.5 · fixed in 5.53.5
    GHSA-qgvg-pr8v-6rr3CVE-2026-27902
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-qgvg-pr8v-6rr3 (CVE-2026-27902), severity medium
    What it is: Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers
    Affected packages:
    - svelte: affected versions >= 5.53.0, < 5.53.5. Fixed in 5.53.5.
    Details: https://github.com/advisories/GHSA-qgvg-pr8v-6rr3
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumFeb 26, 2026

    Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`

    • svelte <= 5.53.4 · fixed in 5.53.5
    GHSA-phwv-c562-gvmhCVE-2026-27901
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-phwv-c562-gvmh (CVE-2026-27901), severity medium
    What it is: Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`
    Affected packages:
    - svelte: affected versions <= 5.53.4. Fixed in 5.53.5.
    Details: https://github.com/advisories/GHSA-phwv-c562-gvmh
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumFeb 19, 2026

    CPU exhaustion in SvelteKit remote form deserialization (experimental only)

    • @sveltejs/kit >= 2.49.0, <= 2.52.1 · fixed in 2.52.2
    GHSA-88qp-p4qg-rqm6
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-88qp-p4qg-rqm6, severity medium
    What it is: CPU exhaustion in SvelteKit remote form deserialization (experimental only)
    Affected packages:
    - @sveltejs/kit: affected versions >= 2.49.0, <= 2.52.1. Fixed in 2.52.2.
    Details: https://github.com/advisories/GHSA-88qp-p4qg-rqm6
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumFeb 19, 2026

    Memory exhaustion in SvelteKit remote form deserialization (experimental only)

    • @sveltejs/kit >= 2.49.0, <= 2.52.1 · fixed in 2.52.2
    GHSA-vrhm-gvg7-fpcf
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-vrhm-gvg7-fpcf, severity medium
    What it is: Memory exhaustion in SvelteKit remote form deserialization (experimental only)
    Affected packages:
    - @sveltejs/kit: affected versions >= 2.49.0, <= 2.52.1. Fixed in 2.52.2.
    Details: https://github.com/advisories/GHSA-vrhm-gvg7-fpcf
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumFeb 19, 2026

    Svelte SSR attribute spreading includes inherited properties from prototype chain

    • svelte <= 5.51.4 · fixed in 5.51.5
    GHSA-crpf-4hrx-3jrpCVE-2026-27125
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-crpf-4hrx-3jrp (CVE-2026-27125), severity medium
    What it is: Svelte SSR attribute spreading includes inherited properties from prototype chain
    Affected packages:
    - svelte: affected versions <= 5.51.4. Fixed in 5.51.5.
    Details: https://github.com/advisories/GHSA-crpf-4hrx-3jrp
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumFeb 19, 2026

    Svelte SSR does not validate dynamic element tag names in `<svelte:element>`

    • svelte <= 5.51.4 · fixed in 5.51.5
    GHSA-m56q-vw4c-c2cpCVE-2026-27122
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-m56q-vw4c-c2cp (CVE-2026-27122), severity medium
    What it is: Svelte SSR does not validate dynamic element tag names in `<svelte:element>`
    Affected packages:
    - svelte: affected versions <= 5.51.4. Fixed in 5.51.5.
    Details: https://github.com/advisories/GHSA-m56q-vw4c-c2cp
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumFeb 19, 2026

    Svelte affected by cross-site scripting via spread attributes in Svelte SSR

    • svelte <= 5.51.4 · fixed in 5.51.5
    GHSA-f7gr-6p89-r883CVE-2026-27121
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-f7gr-6p89-r883 (CVE-2026-27121), severity medium
    What it is: Svelte affected by cross-site scripting via spread attributes in Svelte SSR
    Affected packages:
    - svelte: affected versions <= 5.51.4. Fixed in 5.51.5.
    Details: https://github.com/advisories/GHSA-f7gr-6p89-r883
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumFeb 19, 2026

    Svelte affected by XSS in SSR `<option>` element

    • svelte >= 5.39.3, < 5.51.5 · fixed in 5.51.5
    GHSA-h7h7-mm68-gmrcCVE-2026-27119
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-h7h7-mm68-gmrc (CVE-2026-27119), severity medium
    What it is: Svelte affected by XSS in SSR `<option>` element
    Affected packages:
    - svelte: affected versions >= 5.39.3, < 5.51.5. Fixed in 5.51.5.
    Details: https://github.com/advisories/GHSA-h7h7-mm68-gmrc
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJan 16, 2026

    svelte is vulnerable to XSS with textarea bind:value

    • svelte >= 3.0.0, < 3.59.2 · fixed in 3.59.2
    GHSA-gw32-9rmw-qwww
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-gw32-9rmw-qwww, severity high
    What it is: svelte is vulnerable to XSS with textarea bind:value
    Affected packages:
    - svelte: affected versions >= 3.0.0, < 3.59.2. Fixed in 3.59.2.
    Details: https://github.com/advisories/GHSA-gw32-9rmw-qwww
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJan 15, 2026

    svelte vulnerable to Cross-site Scripting

    • svelte >= 5.46.0, <= 5.46.3 · fixed in 5.46.4
    GHSA-6738-r8g5-qwp3CVE-2025-15265
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-6738-r8g5-qwp3 (CVE-2025-15265), severity medium
    What it is: svelte vulnerable to Cross-site Scripting
    Affected packages:
    - svelte: affected versions >= 5.46.0, <= 5.46.3. Fixed in 5.46.4.
    Details: https://github.com/advisories/GHSA-6738-r8g5-qwp3
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJan 15, 2026

    @sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)

    • @sveltejs/kit >= 2.49.0, <= 2.49.4 · fixed in 2.49.5
    GHSA-j2f3-wq62-6q46CVE-2026-22803
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-j2f3-wq62-6q46 (CVE-2026-22803), severity high
    What it is: @sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
    Affected packages:
    - @sveltejs/kit: affected versions >= 2.49.0, <= 2.49.4. Fixed in 2.49.5.
    Details: https://github.com/advisories/GHSA-j2f3-wq62-6q46
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJan 15, 2026

    SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering

    • @sveltejs/kit >= 2.19.0, <= 2.49.4 · fixed in 2.49.5
    GHSA-j62c-4x62-9r35CVE-2025-67647
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-j62c-4x62-9r35 (CVE-2025-67647), severity high
    What it is: SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
    Affected packages:
    - @sveltejs/kit: affected versions >= 2.19.0, <= 2.49.4. Fixed in 2.49.5.
    Details: https://github.com/advisories/GHSA-j62c-4x62-9r35
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumApr 14, 2025

    @sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params

    • @sveltejs/kit >= 2.0.0, < 2.20.6 · fixed in 2.20.6
    GHSA-6q87-84jw-cjhpCVE-2025-32388
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-6q87-84jw-cjhp (CVE-2025-32388), severity medium
    What it is: @sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params
    Affected packages:
    - @sveltejs/kit: affected versions >= 2.0.0, < 2.20.6. Fixed in 2.20.6.
    Details: https://github.com/advisories/GHSA-6q87-84jw-cjhp
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • lowNov 25, 2024

    @sveltejs/kit vulnerable to XSS on dev mode 404 page

    • @sveltejs/kit < 2.8.3 · fixed in 2.8.3
    GHSA-rjjv-87mx-6x3hCVE-2024-53261
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-rjjv-87mx-6x3h (CVE-2024-53261), severity low
    What it is: @sveltejs/kit vulnerable to XSS on dev mode 404 page
    Affected packages:
    - @sveltejs/kit: affected versions < 2.8.3. Fixed in 2.8.3.
    Details: https://github.com/advisories/GHSA-rjjv-87mx-6x3h
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • lowNov 25, 2024

    @sveltejs/kit has unescaped error message included on error page

    • @sveltejs/kit < 2.8.3 · fixed in 2.8.3
    GHSA-mh2x-fcqh-fmqvCVE-2024-53262
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-mh2x-fcqh-fmqv (CVE-2024-53262), severity low
    What it is: @sveltejs/kit has unescaped error message included on error page
    Affected packages:
    - @sveltejs/kit: affected versions < 2.8.3. Fixed in 2.8.3.
    Details: https://github.com/advisories/GHSA-mh2x-fcqh-fmqv
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumAug 30, 2024

    Svelte has a potential mXSS vulnerability due to improper HTML escaping

    • svelte < 4.2.19 · fixed in 4.2.19
    GHSA-8266-84wp-wv5cCVE-2024-45047
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-8266-84wp-wv5c (CVE-2024-45047), severity medium
    What it is: Svelte has a potential mXSS vulnerability due to improper HTML escaping
    Affected packages:
    - svelte: affected versions < 4.2.19. Fixed in 4.2.19.
    Details: https://github.com/advisories/GHSA-8266-84wp-wv5c
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJan 24, 2024

    Sending a GET or HEAD request with a body crashes SvelteKit

    • @sveltejs/kit >= 2.0.0, < 2.4.3 · fixed in 2.4.3
    GHSA-g5m6-hxpp-fc49CVE-2024-23641
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-g5m6-hxpp-fc49 (CVE-2024-23641), severity high
    What it is: Sending a GET or HEAD request with a body crashes SvelteKit
    Affected packages:
    - @sveltejs/kit: affected versions >= 2.0.0, < 2.4.3. Fixed in 2.4.3.
    Details: https://github.com/advisories/GHSA-g5m6-hxpp-fc49
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highApr 7, 2023

    SvelteKit framework has Insufficient CSRF protection for CORS requests

    • @sveltejs/kit < 1.15.2 · fixed in 1.15.2
    GHSA-gv7g-x59x-wf8fCVE-2023-29008
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-gv7g-x59x-wf8f (CVE-2023-29008), severity high
    What it is: SvelteKit framework has Insufficient CSRF protection for CORS requests
    Affected packages:
    - @sveltejs/kit: affected versions < 1.15.2. Fixed in 1.15.2.
    Details: https://github.com/advisories/GHSA-gv7g-x59x-wf8f
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highApr 4, 2023

    SvelteKit vulnerable to Cross-Site Request Forgery

    • @sveltejs/kit < 1.15.1 · fixed in 1.15.1
    GHSA-5p75-vc5g-8rv2CVE-2023-29003
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-5p75-vc5g-8rv2 (CVE-2023-29003), severity high
    What it is: SvelteKit vulnerable to Cross-Site Request Forgery
    Affected packages:
    - @sveltejs/kit: affected versions < 1.15.1. Fixed in 1.15.1.
    Details: https://github.com/advisories/GHSA-5p75-vc5g-8rv2
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.

From the GitHub Advisory Database, refreshed hourly. Full history on GitHub.

Keeping SvelteKit patched

  • npm audit (or pnpm audit) lists known vulnerable packages in your lockfile, including ones pulled in by other packages.
  • Turn on Dependabot for your GitHub repo and it opens the upgrade for you when an advisory lands.
  • A patched framework doesn't cover your own setup: headers, cookies and HTTPS. The free check looks at those.