Sveltekit · Sveltekit · CVE-2026-82258
**Name of the Vulnerable Software and Affected Versions**
SvelteKit versions 2.38.0 through 2.60.0
**Description**
A race condition exists in the `query.batch` function. This flaw allows concurrent requests from different users to merge under a single request context, enabling attackers to exploit specific timing conditions to access sensitive data from other users' concurrent requests.
**Recommendations**
Update SvelteKit to version 2.60.1 or later.