SvelteKit versions from 2.38.0 before 2.60.1 contain a...
Moderate severity
Unreviewed
Published
Aug 28, 2026
to the GitHub Advisory Database
•
Updated Aug 31, 2026
Description
Published by the National Vulnerability Database
Aug 28, 2026
Published to the GitHub Advisory Database
Aug 28, 2026
Last updated
Aug 31, 2026
SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing conditions to access sensitive data from other users' concurrent requests.
References