npm

@sveltejs/kit

View on npm registry
16 Total advisories
16 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 4.3
npm

GHSA-866w-xmhq-wj7x

SvelteKit: Prototype pollution in file input deletion path in remote-function forms

MEDIUM 5.3
npm

GHSA-wqjv-9729-c5q2

SvelteKit: Big remote form function payloads can cause Node process to crash

UNKNOWN
npm

GHSA-hgv7-v322-mmgr

@sveltejs/kit: `query.batch` cross-talk

UNKNOWN
npm

CVE-2026-40073

@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass

UNKNOWN
npm

CVE-2026-40074

@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service

UNKNOWN
npm

GHSA-fpg4-jhqr-589c

SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)

UNKNOWN
npm

GHSA-vrhm-gvg7-fpcf

Memory exhaustion in SvelteKit remote form deserialization (experimental only)

UNKNOWN
npm

GHSA-88qp-p4qg-rqm6

CPU exhaustion in SvelteKit remote form deserialization (experimental only)

UNKNOWN
npm

CVE-2025-67647

SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering

UNKNOWN
npm

CVE-2026-22803

@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)

MEDIUM 5.4
npm

CVE-2025-32388

@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params

NONE 0.0
npm

CVE-2024-53261

@sveltejs/kit vulnerable to XSS on dev mode 404 page

MEDIUM 4.2
npm

CVE-2024-53262

@sveltejs/kit has unescaped error message included on error page

HIGH 7.5
npm

CVE-2024-23641

Sending a GET or HEAD request with a body crashes SvelteKit

HIGH 8.8
npm

CVE-2023-29008

SvelteKit framework has Insufficient CSRF protection for CORS requests

HIGH 8.8
npm

CVE-2023-29003

SvelteKit vulnerable to Cross-Site Request Forgery

Ready to move

Start Securing

Free, no credit card | First findings in minutes