Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7 advisories

Loading
Vite's `server.fs` settings were not applied to HTML files Low
CVE-2025-58752 was published for vite (npm) Sep 9, 2025
orihjfrog Credited to orihjfrog and dominikg dominikg dominikg
devalue prototype pollution vulnerability High
CVE-2025-57820 was published for devalue (npm) Aug 26, 2025
apyatko Credited to apyatko, Rich-Harris, and dominikg Rich-Harris Rich-Harris
dominikg dominikg
@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params Moderate
CVE-2025-32388 was published for @sveltejs/kit (npm) Apr 14, 2025
kkarikos Credited to kkarikos, Rich-Harris, dominikg, and dummdidumm Rich-Harris Rich-Harris
dominikg dominikg dummdidumm dummdidumm
@sveltejs/kit has unescaped error message included on error page Low
CVE-2024-53262 was published for @sveltejs/kit (npm) Nov 25, 2024
dominikg Credited to dominikg, teemingc, and benmccann teemingc teemingc
benmccann benmccann
Sending a GET or HEAD request with a body crashes SvelteKit High
CVE-2024-23641 was published for @sveltejs/adapter-node (npm) Jan 24, 2024
kamerat Credited to kamerat, Rich-Harris, Conduitry, dominikg, and benmccann Rich-Harris Rich-Harris
Conduitry Conduitry dominikg dominikg benmccann benmccann
SvelteKit framework has Insufficient CSRF protection for CORS requests High
CVE-2023-29008 was published for @sveltejs/kit (npm) Apr 7, 2023
Ry0taK Credited to Ry0taK, benmccann, dominikg, and Conduitry benmccann benmccann
dominikg dominikg Conduitry Conduitry
SvelteKit vulnerable to Cross-Site Request Forgery High
CVE-2023-29003 was published for @sveltejs/kit (npm) Apr 4, 2023
v1ktor0t Credited to v1ktor0t, benmccann, Conduitry, teemingc, and dominikg benmccann benmccann
Conduitry Conduitry teemingc teemingc dominikg dominikg
ProTip! Advisories are also available from the GraphQL API