GHSA-m99x-q38g-c4c6Medium

SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows...

Published
August 28, 2026
Last Modified
August 28, 2026

🔗 CVE IDs covered (1)

📋 Description

SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing conditions to access sensitive data from other users' concurrent requests.

🔗 References (4)