{"schema_version":1,"title":"@sveltejs/kit (npm) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 19 vulnerabilities in @sveltejs/kit (npm): 0 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-82261, was published on 28 August 2026.","url":"https://junglewise.ai/threats/technologies/sveltejs-kit","json_url":"https://junglewise.ai/threats/technologies/sveltejs-kit.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/sveltejs-kit","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":5,"all_time":19,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":6,"last_90_days":9,"last_365_days":14},"latest":[{"cve":"CVE-2026-82261","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82261-sveltekit-cpu-exhaustion-in-remote-form-deserialization","title":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulner","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:39.25+00:00","url":"https://junglewise.ai/threats/cve-2026-82261-sveltekit-cpu-exhaustion-in-remote-form-deserialization"},{"cve":"CVE-2026-82260","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82260-sveltekit-memory-exhaustion-in-remote-form-deserialization","title":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:39.1+00:00","url":"https://junglewise.ai/threats/cve-2026-82260-sveltekit-memory-exhaustion-in-remote-form-deserialization"},{"cve":"CVE-2026-82259","cvss":7.5,"epss":0.0053,"slug":"cve-2026-82259-sveltekit-deserialization-expansion-in-form-remote-function","title":"SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote fu","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:38.953+00:00","url":"https://junglewise.ai/threats/cve-2026-82259-sveltekit-deserialization-expansion-in-form-remote-function"},{"cve":"CVE-2026-82258","cvss":4.8,"epss":0.0024,"slug":"cve-2026-82258-sveltejs-kit-query-batch-cross-talk-vulnerability","title":"SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.77+00:00","url":"https://junglewise.ai/threats/cve-2026-82258-sveltejs-kit-query-batch-cross-talk-vulnerability"},{"cve":"CVE-2026-82257","cvss":4.3,"epss":0.0036,"slug":"cve-2026-82257-sveltekit-prototype-pollution-in-file-input-deletion","title":"SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arb","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.607+00:00","url":"https://junglewise.ai/threats/cve-2026-82257-sveltekit-prototype-pollution-in-file-input-deletion"},{"cve":"CVE-2026-82256","cvss":5.3,"epss":0.0042,"slug":"cve-2026-82256-sveltekit-unhandled-promise-rejection-in-form-payload-handling","title":"SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sendi","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.457+00:00","url":"https://junglewise.ai/threats/cve-2026-82256-sveltekit-unhandled-promise-rejection-in-form-payload-handling"},{"cve":"CVE-2026-66062","cvss":5.3,"epss":0.0051,"slug":"cve-2026-66062-svelte-sveltekit-redos-in-accept-header-content-negotiation","title":"Svelte SvelteKit ReDoS in Accept header content negotiation","severity":"medium","exploited":false,"published_at":"2026-08-07T16:50:02+00:00","url":"https://junglewise.ai/threats/cve-2026-66062-svelte-sveltekit-redos-in-accept-header-content-negotiation"},{"cvss":4.3,"slug":"sveltekit-prototype-pollution-in-remote-function-forms-d7c09314","title":"SvelteKit prototype pollution in remote-function forms","severity":"medium","exploited":false,"published_at":"2026-07-24T15:58:05+00:00","url":"https://junglewise.ai/threats/sveltekit-prototype-pollution-in-remote-function-forms-d7c09314"},{"cvss":5.3,"slug":"svelte-sveltekit-denial-of-service-via-large-form-payloads-2ac113a1","title":"Svelte SvelteKit Denial of Service via large form payloads","severity":"medium","exploited":false,"published_at":"2026-07-24T15:50:40+00:00","url":"https://junglewise.ai/threats/svelte-sveltekit-denial-of-service-via-large-form-payloads-2ac113a1"},{"cvss":5.9,"slug":"svelte-sveltekit-cross-user-data-disclosure-in-query-batch-72bcef47","title":"Svelte SvelteKit cross-user data disclosure in query.batch","severity":"medium","exploited":false,"published_at":"2026-05-21T17:59:05+00:00","url":"https://junglewise.ai/threats/svelte-sveltekit-cross-user-data-disclosure-in-query-batch-72bcef47"},{"cve":"CVE-2026-40074","cvss":7.5,"epss":0.0061,"slug":"cve-2026-40074-svelte-sveltekit-denial-of-service-in-redirect-function","title":"Svelte SvelteKit denial of service in redirect function","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:12.513+00:00","url":"https://junglewise.ai/threats/cve-2026-40074-svelte-sveltekit-denial-of-service-in-redirect-function"},{"cve":"CVE-2026-40073","cvss":7.5,"epss":0.0096,"slug":"cve-2026-40073-svelte-sveltekit-body-size-limit-bypass-in-adapter-node","title":"Svelte SvelteKit body size limit bypass in adapter-node","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:12.357+00:00","url":"https://junglewise.ai/threats/cve-2026-40073-svelte-sveltekit-body-size-limit-bypass-in-adapter-node"},{"cve":"CVE-2026-22803","cvss":4,"epss":0.006,"slug":"cve-2026-22803-sveltekit-memory-amplification-dos-in-form-deserializer","title":"SvelteKit memory amplification DoS in form deserializer","severity":"medium","exploited":false,"published_at":"2026-01-15T18:10:52+00:00","url":"https://junglewise.ai/threats/cve-2026-22803-sveltekit-memory-amplification-dos-in-form-deserializer"},{"cve":"CVE-2025-67647","cvss":4,"epss":0.0053,"slug":"cve-2025-67647-sveltekit-denial-of-service-and-ssrf-in-prerendering","title":"SvelteKit denial of service and SSRF in prerendering","severity":"medium","exploited":false,"published_at":"2026-01-15T18:09:59+00:00","url":"https://junglewise.ai/threats/cve-2025-67647-sveltekit-denial-of-service-and-ssrf-in-prerendering"},{"cve":"CVE-2025-32388","cvss":3.1,"epss":0.003,"slug":"cve-2025-32388-sveltekit-cross-site-scripting-via-tracked-search-parameters","title":"SvelteKit cross-site scripting via tracked search parameters","severity":"low","exploited":false,"published_at":"2025-04-14T19:10:42+00:00","url":"https://junglewise.ai/threats/cve-2025-32388-sveltekit-cross-site-scripting-via-tracked-search-parameters"},{"cve":"CVE-2024-53261","cvss":3.1,"epss":0.0033,"slug":"cve-2024-53261-sveltejs-kit-cross-site-scripting-in-dev-mode-404-page","title":"SvelteJS Kit cross-site scripting in dev mode 404 page","severity":"low","exploited":false,"published_at":"2024-11-25T15:33:19+00:00","url":"https://junglewise.ai/threats/cve-2024-53261-sveltejs-kit-cross-site-scripting-in-dev-mode-404-page"},{"cve":"CVE-2024-53262","cvss":3.1,"epss":0.0048,"slug":"cve-2024-53262-sveltejs-kit-unescaped-error-message-xss-on-error-page","title":"SvelteJS Kit unescaped error message XSS on error page","severity":"low","exploited":false,"published_at":"2024-11-25T15:32:45+00:00","url":"https://junglewise.ai/threats/cve-2024-53262-sveltejs-kit-unescaped-error-message-xss-on-error-page"},{"cve":"CVE-2023-29008","cvss":3.1,"epss":0.0037,"slug":"cve-2023-29008-sveltekit-insufficient-csrf-protection-in-cors-requests","title":"SvelteKit insufficient CSRF protection in CORS requests","severity":"low","exploited":false,"published_at":"2023-04-07T19:23:31+00:00","url":"https://junglewise.ai/threats/cve-2023-29008-sveltekit-insufficient-csrf-protection-in-cors-requests"},{"cve":"CVE-2023-29003","cvss":3.1,"epss":0.0056,"slug":"cve-2023-29003-sveltekit-insufficient-cross-site-request-forgery-protection","title":"SvelteKit insufficient cross-site request forgery protection","severity":"low","exploited":false,"published_at":"2023-04-04T21:20:47+00:00","url":"https://junglewise.ai/threats/cve-2023-29003-sveltekit-insufficient-cross-site-request-forgery-protection"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"flowise (npm)","slug":"flowise","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/flowise"},{"name":"vm2 (npm)","slug":"vm2","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/vm2"},{"name":"@budibase/server (npm)","slug":"budibase-server","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/budibase-server"},{"name":"directus (npm)","slug":"directus","vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/directus"},{"name":"nocodb (npm)","slug":"nocodb","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/nocodb"},{"name":"hono (npm)","slug":"hono","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/hono"},{"name":"parse-server (npm)","slug":"parse-server","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/parse-server"},{"name":"dompurify (npm)","slug":"dompurify","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/dompurify"},{"name":"ghost (npm)","slug":"ghost","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/ghost"},{"name":"flowise-components (npm)","slug":"flowise-components","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/flowise-components"},{"name":"astro (npm)","slug":"astro","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/astro"},{"name":"@anthropic-ai/claude-code (npm)","slug":"anthropic-ai-claude-code","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/anthropic-ai-claude-code"}],"technology":{"hub":true,"name":"@sveltejs/kit (npm)","slug":"sveltejs-kit","vendor":{"name":"npm","slug":"npm","url":"https://junglewise.ai/threats/vendors/npm"},"aliases":[],"homepage":"https://kit.svelte.dev/","repo_url":"https://github.com/sveltejs/kit","description":"A framework for building web applications using Svelte components.","url":"https://junglewise.ai/threats/technologies/sveltejs-kit"},"most_severe":[{"cve":"CVE-2026-40073","cvss":7.5,"epss":0.0096,"slug":"cve-2026-40073-svelte-sveltekit-body-size-limit-bypass-in-adapter-node","title":"Svelte SvelteKit body size limit bypass in adapter-node","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:12.357+00:00","url":"https://junglewise.ai/threats/cve-2026-40073-svelte-sveltekit-body-size-limit-bypass-in-adapter-node"},{"cve":"CVE-2026-40074","cvss":7.5,"epss":0.0061,"slug":"cve-2026-40074-svelte-sveltekit-denial-of-service-in-redirect-function","title":"Svelte SvelteKit denial of service in redirect function","severity":"high","exploited":false,"published_at":"2026-04-10T17:17:12.513+00:00","url":"https://junglewise.ai/threats/cve-2026-40074-svelte-sveltekit-denial-of-service-in-redirect-function"},{"cve":"CVE-2026-82259","cvss":7.5,"epss":0.0053,"slug":"cve-2026-82259-sveltekit-deserialization-expansion-in-form-remote-function","title":"SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote fu","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:38.953+00:00","url":"https://junglewise.ai/threats/cve-2026-82259-sveltekit-deserialization-expansion-in-form-remote-function"},{"cve":"CVE-2026-82261","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82261-sveltekit-cpu-exhaustion-in-remote-form-deserialization","title":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulner","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:39.25+00:00","url":"https://junglewise.ai/threats/cve-2026-82261-sveltekit-cpu-exhaustion-in-remote-form-deserialization"},{"cve":"CVE-2026-82260","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82260-sveltekit-memory-exhaustion-in-remote-form-deserialization","title":"SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled","severity":"high","exploited":false,"published_at":"2026-08-28T12:16:39.1+00:00","url":"https://junglewise.ai/threats/cve-2026-82260-sveltekit-memory-exhaustion-in-remote-form-deserialization"},{"cvss":5.9,"slug":"svelte-sveltekit-cross-user-data-disclosure-in-query-batch-72bcef47","title":"Svelte SvelteKit cross-user data disclosure in query.batch","severity":"medium","exploited":false,"published_at":"2026-05-21T17:59:05+00:00","url":"https://junglewise.ai/threats/svelte-sveltekit-cross-user-data-disclosure-in-query-batch-72bcef47"},{"cve":"CVE-2026-66062","cvss":5.3,"epss":0.0051,"slug":"cve-2026-66062-svelte-sveltekit-redos-in-accept-header-content-negotiation","title":"Svelte SvelteKit ReDoS in Accept header content negotiation","severity":"medium","exploited":false,"published_at":"2026-08-07T16:50:02+00:00","url":"https://junglewise.ai/threats/cve-2026-66062-svelte-sveltekit-redos-in-accept-header-content-negotiation"},{"cve":"CVE-2026-82256","cvss":5.3,"epss":0.0042,"slug":"cve-2026-82256-sveltekit-unhandled-promise-rejection-in-form-payload-handling","title":"SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sendi","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.457+00:00","url":"https://junglewise.ai/threats/cve-2026-82256-sveltekit-unhandled-promise-rejection-in-form-payload-handling"},{"cvss":5.3,"slug":"svelte-sveltekit-denial-of-service-via-large-form-payloads-2ac113a1","title":"Svelte SvelteKit Denial of Service via large form payloads","severity":"medium","exploited":false,"published_at":"2026-07-24T15:50:40+00:00","url":"https://junglewise.ai/threats/svelte-sveltekit-denial-of-service-via-large-form-payloads-2ac113a1"},{"cve":"CVE-2026-82258","cvss":4.8,"epss":0.0024,"slug":"cve-2026-82258-sveltejs-kit-query-batch-cross-talk-vulnerability","title":"SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to","severity":"medium","exploited":false,"published_at":"2026-08-28T12:16:38.77+00:00","url":"https://junglewise.ai/threats/cve-2026-82258-sveltejs-kit-query-batch-cross-talk-vulnerability"}],"generated_at":"2026-09-26T10:14:00.201383+00:00"}