PT-2026-83110 · Sveltekit · Sveltekit

·

CVE-2026-82258

·

Published

2026-05-21

·

Updated

2026-08-28

CVSS v4.0

5.9

Medium

VectorAV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SvelteKit versions 2.38.0 through 2.60.0
Description A race condition exists in the query.batch function. This flaw allows concurrent requests from different users to merge under a single request context, enabling attackers to exploit specific timing conditions to access sensitive data from other users' concurrent requests.
Recommendations Update SvelteKit to version 2.60.1 or later.

Exploit

Fix

Information Disclosure

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82258
GHSA-HGV7-V322-MMGR

Affected Products

Sveltekit