Svelte Ecosystem Releases Security Patches for 5 Vulnerabilities
By
tobr
Baker's choice. Dense with flavour, light on filler.
Summary
The Svelte ecosystem has released security patches for 5 vulnerabilities affecting multiple packages including devalue, svelte, @sveltejs/kit, and @sveltejs/adapter-node. Users are urged to upgrade to patched versions immediately, with cross-dependent packages already including upgraded dependencies. The article acknowledges security researchers and Vercel's security team for responsible disclosure and collaboration in fixing the vulnerabilities.
Key quotes
· 4 pulledWe've released patches for 5 vulnerabilities across devalue, svelte, @sveltejs/kit, and @sveltejs/adapter-node.
Upgrade now: If you're using any of these packages, upgrade them to their corresponding non-vulnerable versions.
For cross-dependent packages — svelte and @sveltejs/kit depend on devalue — patched versions already include upgraded dependencies.
We're extremely thankful to all of the security researchers who responsibly disclosed these vulnerabilities and worked with us to get them fixed, to the security team at Vercel who helped us navigate the disclosure.
You might also wanna read
Why Security Through Obscurity Still Matters as a Practical Defense Layer
The article challenges the common developer mantra that "security through obscurity is bad," arguing that obscurity (like JavaScript obfusca
Scratch's ongoing security challenges with SVG sanitization
The article discusses the security challenges Scratch faces with SVG sanitization. Scratch parses user-generated (attacker-controlled) SVG c
CT Log Explorer: A Tool for Browsing Certificate Transparency Logs
CT Log Explorer is a tool for browsing Certificate Transparency logs, which are public records of SSL/TLS certificates issued by Certificate
Security Warning: Exposed Supabase API Keys Leave Databases Publicly Accessible
The article describes a security vulnerability where developers often leave their Supabase databases publicly accessible by exposing API key
Next.js Security Update: Two New React Server Component Vulnerabilities Identified
Two new security vulnerabilities (CVE-2025-55183 and CVE-2025-55184) have been discovered in React Server Components (RSC) protocol, affecti
Critical Security Vulnerability in React Server Components (CVE-2025-55182) Allows Remote Code Execution
The React team disclosed a critical security vulnerability (CVE-2025-55182) rated CVSS 10.0 that allows unauthenticated remote code executio
