CVE-2026-82258
SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing conditions to access sensitive data from other users' concurrent requests.
| CWE | CWE-362 |
| Vendor | sveltejs |
| Product | kit |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for sveltejs kit
Be the first to know when new unknown vulnerabilities affecting sveltejs kit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
sveltejs / kit
2.38.0 < 2.60.1
References
Credits
๐ rafabd1 elliott-with-the-longest-name-on-github dummdidumm