Junglewise Threat Intelligence

CVE-2026-27118: Svelte adapter-vercel cache poisoning via ISR query parameter

CVE-2026-27118 · Severity: medium · CVSS 4 · Published 2026-02-19

Vendors: npm, Svelte.

Executive brief

The @sveltejs/adapter-vercel library, used to deploy Svelte web applications to Vercel's hosting platform, contains a cache poisoning vulnerability that allows attackers to cause personalized user responses to be cached and served to other users. An attacker can exploit this by crafting a malicious link that tricks an authenticated victim into triggering the vulnerability, resulting in sensitive information being exposed across the user base. While Vercel's Web Application Firewall currently provides protection, developers should upgrade to patch this flaw immediately.

Technical details

The vulnerability exists in @sveltejs/adapter-vercel versions prior to 6.3.2 and stems from improper handling of an internal query parameter used for Incremental Static Regeneration (ISR). This parameter, intended for internal use only, is accessible on all application routes, allowing an attacker to trigger caching of user-specific responses intended for different users. The attack requires user interaction—a victim must visit an attacker-controlled link while authenticated to the application. Upon successful exploitation, the attacker can cause sensitive responses (e.g., personalized data, authentication tokens, private information) to be cached and subsequently served to other authenticated users accessing the same route. The vulnerability is classified as cache poisoning (CWE-346) with a CVSS v4 score of 5.3. A patch is available in version 6.3.2.

Affected products

  • Svelte adapter-vercel <6.3.2

Timeline

  • 2026-02-18: disclosed
  • 2026-02-19: patched: Version 6.3.2 released

References