Server Side Request Forgery Vulnerability in SvelteKit Framework
CVE-2025-67647
8.4HIGH
What is CVE-2025-67647?
The SvelteKit framework, designed for efficient web application development, is susceptible to a server side request forgery (SSRF) and potential denial of service (DoS) under specific conditions. Versions from 2.19.0 to 2.49.4 may experience a DoS when at least one prerendered route is present and when using the adapter-node without a correctly set ORIGIN environment variable, especially if there is no reverse proxy that validates the Host header. The issue has been resolved in version 2.49.5, reinforcing the need for timely updates to safeguard your applications.
Affected Version(s)
kit >= 2.19.0, < 2.49.5
