17 Total advisories
17 Vulnerabilities
0 Malware
Dependency scanning
Check whether @sveltejs/kit is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-82258
@sveltejs/kit: `query.batch` cross-talk
MEDIUM 5.3
CVE-2026-82256
SvelteKit: Big remote form function payloads can cause Node process to crash
MEDIUM 4.3
CVE-2026-82257
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
UNKNOWN
CVE-2026-82259
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
MEDIUM 5.3
CVE-2026-66062
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
UNKNOWN
CVE-2026-40073
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
UNKNOWN
CVE-2026-40074
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
UNKNOWN
GHSA-vrhm-gvg7-fpcf
Memory exhaustion in SvelteKit remote form deserialization (experimental only)
UNKNOWN
GHSA-88qp-p4qg-rqm6
CPU exhaustion in SvelteKit remote form deserialization (experimental only)
UNKNOWN
CVE-2025-67647
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
UNKNOWN
CVE-2026-22803
@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
MEDIUM 5.4
CVE-2025-32388
@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params
NONE 0.0
CVE-2024-53261
@sveltejs/kit vulnerable to XSS on dev mode 404 page
MEDIUM 4.2
CVE-2024-53262
@sveltejs/kit has unescaped error message included on error page
HIGH 7.5
CVE-2024-23641
Sending a GET or HEAD request with a body crashes SvelteKit
HIGH 8.8
CVE-2023-29008
SvelteKit framework has Insufficient CSRF protection for CORS requests
HIGH 8.8
CVE-2023-29003
SvelteKit vulnerable to Cross-Site Request Forgery
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes