Server Side Request Forgery Vulnerability in SvelteKit Framework
CVE-2025-67647

8.4HIGH

Key Information:

Vendor

Sveltejs

Status
Vendor
CVE Published:
15 January 2026

What is CVE-2025-67647?

The SvelteKit framework, designed for efficient web application development, is susceptible to a server side request forgery (SSRF) and potential denial of service (DoS) under specific conditions. Versions from 2.19.0 to 2.49.4 may experience a DoS when at least one prerendered route is present and when using the adapter-node without a correctly set ORIGIN environment variable, especially if there is no reverse proxy that validates the Host header. The issue has been resolved in version 2.49.5, reinforcing the need for timely updates to safeguard your applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

kit >= 2.19.0, < 2.49.5

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.