npm

@sveltejs/kit

View on npm registry
17 Total advisories
17 Vulnerabilities
0 Malware

Dependency scanning

Check whether @sveltejs/kit is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
npm

CVE-2026-82258

@sveltejs/kit: `query.batch` cross-talk

MEDIUM 5.3
npm

CVE-2026-82256

SvelteKit: Big remote form function payloads can cause Node process to crash

MEDIUM 4.3
npm

CVE-2026-82257

SvelteKit: Prototype pollution in file input deletion path in remote-function forms

UNKNOWN
npm

CVE-2026-82259

SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)

MEDIUM 5.3
npm

CVE-2026-66062

SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header

UNKNOWN
npm

CVE-2026-40073

@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass

UNKNOWN
npm

CVE-2026-40074

@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service

UNKNOWN
npm

GHSA-vrhm-gvg7-fpcf

Memory exhaustion in SvelteKit remote form deserialization (experimental only)

UNKNOWN
npm

GHSA-88qp-p4qg-rqm6

CPU exhaustion in SvelteKit remote form deserialization (experimental only)

UNKNOWN
npm

CVE-2025-67647

SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering

UNKNOWN
npm

CVE-2026-22803

@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)

MEDIUM 5.4
npm

CVE-2025-32388

@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params

NONE 0.0
npm

CVE-2024-53261

@sveltejs/kit vulnerable to XSS on dev mode 404 page

MEDIUM 4.2
npm

CVE-2024-53262

@sveltejs/kit has unescaped error message included on error page

HIGH 7.5
npm

CVE-2024-23641

Sending a GET or HEAD request with a body crashes SvelteKit

HIGH 8.8
npm

CVE-2023-29008

SvelteKit framework has Insufficient CSRF protection for CORS requests

HIGH 8.8
npm

CVE-2023-29003

SvelteKit vulnerable to Cross-Site Request Forgery

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes