PT-2026-83110 · Sveltekit · Sveltekit
CVSS v4.0
5.9
Medium
| Vector | AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SvelteKit versions 2.38.0 through 2.60.0
Description
A race condition exists in the
query.batch function. This flaw allows concurrent requests from different users to merge under a single request context, enabling attackers to exploit specific timing conditions to access sensitive data from other users' concurrent requests.Recommendations
Update SvelteKit to version 2.60.1 or later.
Exploit
Fix
Information Disclosure
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sveltekit