SvelteKit vulnerabilities and security advisories
The newest reviewed advisories for @sveltejs/kit and svelte on npm. Each one shows which versions are affected, which version fixes it, and a prompt that has your AI agent check your project and upgrade only if it needs to.
Get an email when SvelteKit has a new one
Email alerts are coming soon. This page updates every hour.
$ latest 30 · 7 critical, high or exploited
- mediumAug 7, 2026
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
- @sveltejs/kit <= 2.70.1 · fixed in 2.70.2
GHSA-29g2-3rmr-qm68CVE-2026-66062prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-29g2-3rmr-qm68 (CVE-2026-66062), severity medium What it is: SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header Affected packages: - @sveltejs/kit: affected versions <= 2.70.1. Fixed in 2.70.2. Details: https://github.com/advisories/GHSA-29g2-3rmr-qm68 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 24, 2026
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
- @sveltejs/kit <= 2.69.0 · fixed in 2.69.1
GHSA-866w-xmhq-wj7xprompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-866w-xmhq-wj7x, severity medium What it is: SvelteKit: Prototype pollution in file input deletion path in remote-function forms Affected packages: - @sveltejs/kit: affected versions <= 2.69.0. Fixed in 2.69.1. Details: https://github.com/advisories/GHSA-866w-xmhq-wj7x Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 24, 2026
SvelteKit: Big remote form function payloads can cause Node process to crash
- @sveltejs/kit <= 2.69.0 · fixed in 2.69.1
GHSA-wqjv-9729-c5q2prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-wqjv-9729-c5q2, severity medium What it is: SvelteKit: Big remote form function payloads can cause Node process to crash Affected packages: - @sveltejs/kit: affected versions <= 2.69.0. Fixed in 2.69.1. Details: https://github.com/advisories/GHSA-wqjv-9729-c5q2 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 21, 2026
@sveltejs/kit: `query.batch` cross-talk
- @sveltejs/kit >= 2.38.0, <= 2.60.0 · fixed in 2.60.1
GHSA-hgv7-v322-mmgrprompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-hgv7-v322-mmgr, severity medium What it is: @sveltejs/kit: `query.batch` cross-talk Affected packages: - @sveltejs/kit: affected versions >= 2.38.0, <= 2.60.0. Fixed in 2.60.1. Details: https://github.com/advisories/GHSA-hgv7-v322-mmgr Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 14, 2026
Svelte: SSR XSS via Insecure Promise Serialization in hydratable
- svelte >= 5.46.0, <= 5.55.6 · fixed in 5.55.7
GHSA-f3cj-j4f6-wq85prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-f3cj-j4f6-wq85, severity medium What it is: Svelte: SSR XSS via Insecure Promise Serialization in hydratable Affected packages: - svelte: affected versions >= 5.46.0, <= 5.55.6. Fixed in 5.55.7. Details: https://github.com/advisories/GHSA-f3cj-j4f6-wq85 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 14, 2026
Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State
- svelte <= 5.55.6 · fixed in 5.55.7
GHSA-rcqx-6q8c-2c42CVE-2026-42573prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-rcqx-6q8c-2c42 (CVE-2026-42573), severity medium What it is: Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State Affected packages: - svelte: affected versions <= 5.55.6. Fixed in 5.55.7. Details: https://github.com/advisories/GHSA-rcqx-6q8c-2c42 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 14, 2026
Svelte: ReDoS in `<svelte:element>` Tag Validation
- svelte >= 5.51.5, <= 5.55.6 · fixed in 5.55.7
GHSA-9rmh-mm8f-r9h6CVE-2026-42567prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-9rmh-mm8f-r9h6 (CVE-2026-42567), severity medium What it is: Svelte: ReDoS in `<svelte:element>` Tag Validation Affected packages: - svelte: affected versions >= 5.51.5, <= 5.55.6. Fixed in 5.55.7. Details: https://github.com/advisories/GHSA-9rmh-mm8f-r9h6 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 14, 2026
Svelte SSR vulnerable to cross-site scripting via spread attributes
- svelte <= 5.55.6 · fixed in 5.55.7
GHSA-pr6f-5x2q-rwfpCVE-2026-42599prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-pr6f-5x2q-rwfp (CVE-2026-42599), severity medium What it is: Svelte SSR vulnerable to cross-site scripting via spread attributes Affected packages: - svelte: affected versions <= 5.55.6. Fixed in 5.55.7. Details: https://github.com/advisories/GHSA-pr6f-5x2q-rwfp Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumApr 10, 2026
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
- @sveltejs/kit <= 2.57.0 · fixed in 2.57.1
GHSA-3f6h-2hrp-w5wxCVE-2026-40074prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-3f6h-2hrp-w5wx (CVE-2026-40074), severity medium What it is: @sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service Affected packages: - @sveltejs/kit: affected versions <= 2.57.0. Fixed in 2.57.1. Details: https://github.com/advisories/GHSA-3f6h-2hrp-w5wx Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highApr 10, 2026
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
- @sveltejs/kit <= 2.57.0 · fixed in 2.57.1
GHSA-2crg-3p73-43xpCVE-2026-40073prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-2crg-3p73-43xp (CVE-2026-40073), severity high What it is: @sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass Affected packages: - @sveltejs/kit: affected versions <= 2.57.0. Fixed in 2.57.1. Details: https://github.com/advisories/GHSA-2crg-3p73-43xp Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowFeb 28, 2026
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
- @sveltejs/kit >= 2.49.0, <= 2.53.2 · fixed in 2.53.3
GHSA-fpg4-jhqr-589cprompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-fpg4-jhqr-589c, severity low What it is: SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only) Affected packages: - @sveltejs/kit: affected versions >= 2.49.0, <= 2.53.2. Fixed in 2.53.3. Details: https://github.com/advisories/GHSA-fpg4-jhqr-589c Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumFeb 26, 2026
Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers
- svelte >= 5.53.0, < 5.53.5 · fixed in 5.53.5
GHSA-qgvg-pr8v-6rr3CVE-2026-27902prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-qgvg-pr8v-6rr3 (CVE-2026-27902), severity medium What it is: Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers Affected packages: - svelte: affected versions >= 5.53.0, < 5.53.5. Fixed in 5.53.5. Details: https://github.com/advisories/GHSA-qgvg-pr8v-6rr3 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumFeb 26, 2026
Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`
- svelte <= 5.53.4 · fixed in 5.53.5
GHSA-phwv-c562-gvmhCVE-2026-27901prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-phwv-c562-gvmh (CVE-2026-27901), severity medium What it is: Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent` Affected packages: - svelte: affected versions <= 5.53.4. Fixed in 5.53.5. Details: https://github.com/advisories/GHSA-phwv-c562-gvmh Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumFeb 19, 2026
CPU exhaustion in SvelteKit remote form deserialization (experimental only)
- @sveltejs/kit >= 2.49.0, <= 2.52.1 · fixed in 2.52.2
GHSA-88qp-p4qg-rqm6prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-88qp-p4qg-rqm6, severity medium What it is: CPU exhaustion in SvelteKit remote form deserialization (experimental only) Affected packages: - @sveltejs/kit: affected versions >= 2.49.0, <= 2.52.1. Fixed in 2.52.2. Details: https://github.com/advisories/GHSA-88qp-p4qg-rqm6 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumFeb 19, 2026
Memory exhaustion in SvelteKit remote form deserialization (experimental only)
- @sveltejs/kit >= 2.49.0, <= 2.52.1 · fixed in 2.52.2
GHSA-vrhm-gvg7-fpcfprompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-vrhm-gvg7-fpcf, severity medium What it is: Memory exhaustion in SvelteKit remote form deserialization (experimental only) Affected packages: - @sveltejs/kit: affected versions >= 2.49.0, <= 2.52.1. Fixed in 2.52.2. Details: https://github.com/advisories/GHSA-vrhm-gvg7-fpcf Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumFeb 19, 2026
Svelte SSR attribute spreading includes inherited properties from prototype chain
- svelte <= 5.51.4 · fixed in 5.51.5
GHSA-crpf-4hrx-3jrpCVE-2026-27125prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-crpf-4hrx-3jrp (CVE-2026-27125), severity medium What it is: Svelte SSR attribute spreading includes inherited properties from prototype chain Affected packages: - svelte: affected versions <= 5.51.4. Fixed in 5.51.5. Details: https://github.com/advisories/GHSA-crpf-4hrx-3jrp Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumFeb 19, 2026
Svelte SSR does not validate dynamic element tag names in `<svelte:element>`
- svelte <= 5.51.4 · fixed in 5.51.5
GHSA-m56q-vw4c-c2cpCVE-2026-27122prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-m56q-vw4c-c2cp (CVE-2026-27122), severity medium What it is: Svelte SSR does not validate dynamic element tag names in `<svelte:element>` Affected packages: - svelte: affected versions <= 5.51.4. Fixed in 5.51.5. Details: https://github.com/advisories/GHSA-m56q-vw4c-c2cp Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumFeb 19, 2026
Svelte affected by cross-site scripting via spread attributes in Svelte SSR
- svelte <= 5.51.4 · fixed in 5.51.5
GHSA-f7gr-6p89-r883CVE-2026-27121prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-f7gr-6p89-r883 (CVE-2026-27121), severity medium What it is: Svelte affected by cross-site scripting via spread attributes in Svelte SSR Affected packages: - svelte: affected versions <= 5.51.4. Fixed in 5.51.5. Details: https://github.com/advisories/GHSA-f7gr-6p89-r883 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumFeb 19, 2026
Svelte affected by XSS in SSR `<option>` element
- svelte >= 5.39.3, < 5.51.5 · fixed in 5.51.5
GHSA-h7h7-mm68-gmrcCVE-2026-27119prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-h7h7-mm68-gmrc (CVE-2026-27119), severity medium What it is: Svelte affected by XSS in SSR `<option>` element Affected packages: - svelte: affected versions >= 5.39.3, < 5.51.5. Fixed in 5.51.5. Details: https://github.com/advisories/GHSA-h7h7-mm68-gmrc Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJan 16, 2026
svelte is vulnerable to XSS with textarea bind:value
- svelte >= 3.0.0, < 3.59.2 · fixed in 3.59.2
GHSA-gw32-9rmw-qwwwprompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-gw32-9rmw-qwww, severity high What it is: svelte is vulnerable to XSS with textarea bind:value Affected packages: - svelte: affected versions >= 3.0.0, < 3.59.2. Fixed in 3.59.2. Details: https://github.com/advisories/GHSA-gw32-9rmw-qwww Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJan 15, 2026
svelte vulnerable to Cross-site Scripting
- svelte >= 5.46.0, <= 5.46.3 · fixed in 5.46.4
GHSA-6738-r8g5-qwp3CVE-2025-15265prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-6738-r8g5-qwp3 (CVE-2025-15265), severity medium What it is: svelte vulnerable to Cross-site Scripting Affected packages: - svelte: affected versions >= 5.46.0, <= 5.46.3. Fixed in 5.46.4. Details: https://github.com/advisories/GHSA-6738-r8g5-qwp3 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJan 15, 2026
@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
- @sveltejs/kit >= 2.49.0, <= 2.49.4 · fixed in 2.49.5
GHSA-j2f3-wq62-6q46CVE-2026-22803prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-j2f3-wq62-6q46 (CVE-2026-22803), severity high What it is: @sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata) Affected packages: - @sveltejs/kit: affected versions >= 2.49.0, <= 2.49.4. Fixed in 2.49.5. Details: https://github.com/advisories/GHSA-j2f3-wq62-6q46 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJan 15, 2026
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
- @sveltejs/kit >= 2.19.0, <= 2.49.4 · fixed in 2.49.5
GHSA-j62c-4x62-9r35CVE-2025-67647prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-j62c-4x62-9r35 (CVE-2025-67647), severity high What it is: SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering Affected packages: - @sveltejs/kit: affected versions >= 2.19.0, <= 2.49.4. Fixed in 2.49.5. Details: https://github.com/advisories/GHSA-j62c-4x62-9r35 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumApr 14, 2025
@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params
- @sveltejs/kit >= 2.0.0, < 2.20.6 · fixed in 2.20.6
GHSA-6q87-84jw-cjhpCVE-2025-32388prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-6q87-84jw-cjhp (CVE-2025-32388), severity medium What it is: @sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params Affected packages: - @sveltejs/kit: affected versions >= 2.0.0, < 2.20.6. Fixed in 2.20.6. Details: https://github.com/advisories/GHSA-6q87-84jw-cjhp Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowNov 25, 2024
@sveltejs/kit vulnerable to XSS on dev mode 404 page
- @sveltejs/kit < 2.8.3 · fixed in 2.8.3
GHSA-rjjv-87mx-6x3hCVE-2024-53261prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-rjjv-87mx-6x3h (CVE-2024-53261), severity low What it is: @sveltejs/kit vulnerable to XSS on dev mode 404 page Affected packages: - @sveltejs/kit: affected versions < 2.8.3. Fixed in 2.8.3. Details: https://github.com/advisories/GHSA-rjjv-87mx-6x3h Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowNov 25, 2024
@sveltejs/kit has unescaped error message included on error page
- @sveltejs/kit < 2.8.3 · fixed in 2.8.3
GHSA-mh2x-fcqh-fmqvCVE-2024-53262prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-mh2x-fcqh-fmqv (CVE-2024-53262), severity low What it is: @sveltejs/kit has unescaped error message included on error page Affected packages: - @sveltejs/kit: affected versions < 2.8.3. Fixed in 2.8.3. Details: https://github.com/advisories/GHSA-mh2x-fcqh-fmqv Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumAug 30, 2024
Svelte has a potential mXSS vulnerability due to improper HTML escaping
- svelte < 4.2.19 · fixed in 4.2.19
GHSA-8266-84wp-wv5cCVE-2024-45047prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-8266-84wp-wv5c (CVE-2024-45047), severity medium What it is: Svelte has a potential mXSS vulnerability due to improper HTML escaping Affected packages: - svelte: affected versions < 4.2.19. Fixed in 4.2.19. Details: https://github.com/advisories/GHSA-8266-84wp-wv5c Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJan 24, 2024
Sending a GET or HEAD request with a body crashes SvelteKit
- @sveltejs/kit >= 2.0.0, < 2.4.3 · fixed in 2.4.3
GHSA-g5m6-hxpp-fc49CVE-2024-23641prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-g5m6-hxpp-fc49 (CVE-2024-23641), severity high What it is: Sending a GET or HEAD request with a body crashes SvelteKit Affected packages: - @sveltejs/kit: affected versions >= 2.0.0, < 2.4.3. Fixed in 2.4.3. Details: https://github.com/advisories/GHSA-g5m6-hxpp-fc49 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highApr 7, 2023
SvelteKit framework has Insufficient CSRF protection for CORS requests
- @sveltejs/kit < 1.15.2 · fixed in 1.15.2
GHSA-gv7g-x59x-wf8fCVE-2023-29008prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-gv7g-x59x-wf8f (CVE-2023-29008), severity high What it is: SvelteKit framework has Insufficient CSRF protection for CORS requests Affected packages: - @sveltejs/kit: affected versions < 1.15.2. Fixed in 1.15.2. Details: https://github.com/advisories/GHSA-gv7g-x59x-wf8f Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highApr 4, 2023
SvelteKit vulnerable to Cross-Site Request Forgery
- @sveltejs/kit < 1.15.1 · fixed in 1.15.1
GHSA-5p75-vc5g-8rv2CVE-2023-29003prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-5p75-vc5g-8rv2 (CVE-2023-29003), severity high What it is: SvelteKit vulnerable to Cross-Site Request Forgery Affected packages: - @sveltejs/kit: affected versions < 1.15.1. Fixed in 1.15.1. Details: https://github.com/advisories/GHSA-5p75-vc5g-8rv2 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now.
From the GitHub Advisory Database, refreshed hourly. Full history on GitHub.
Keeping SvelteKit patched
npm audit(orpnpm audit) lists known vulnerable packages in your lockfile, including ones pulled in by other packages.- Turn on Dependabot for your GitHub repo and it opens the upgrade for you when an advisory lands.
- A patched framework doesn't cover your own setup: headers, cookies and HTTPS. The free check looks at those.