Vulnerabilities/

@sveltejs/kit: `query.batch` cross-talk

Severity:
Medium

Description

query.batch() could, under very rare and specific timings, cause concurrent requests from different users to merge and resolve under single request context, enabling cross-user data disclosure.

Recommendation

Update the @sveltejs/kit package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@sveltejs/kit
Anything's wrong? Let us know Last updated on May 21, 2026