Package compatibility
SvelteKit 1.0
What Node.js versions does this SvelteKit version support?
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Declared Node.js requirement
- engines.node
- >=16.14
- Tip version
- 1.0.0
- Source
- npm Registry (engines.node)
Node.js compatibility matrix
Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.
Other SvelteKit lines
Security
Advisories affecting SvelteKit 1.0 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 9
- Known exploited
- 0
- Highest CVSS
- —
- CVE-2026-66062GHSA-29g2-3rmr-qm68
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
- Affected:
- <2.70.2
- Fixed in:
- 2.70.2
- Source:
- OSV source
- CVE-2026-82257GHSA-866w-xmhq-wj7x
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
- Affected:
- <2.69.1
- Fixed in:
- 2.69.1
- Source:
- OSV source
- CVE-2026-82256GHSA-wqjv-9729-c5q2
SvelteKit: Big remote form function payloads can cause Node process to crash
- Affected:
- <2.69.1
- Fixed in:
- 2.69.1
- Source:
- OSV source
- CVE-2026-40074GHSA-3f6h-2hrp-w5wx
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
- Affected:
- <2.57.1
- Fixed in:
- 2.57.1
- Source:
- OSV source · Advisory
- CVE-2026-40073GHSA-2crg-3p73-43xp
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
- Affected:
- <2.57.1
- Fixed in:
- 2.57.1
- Source:
- OSV source · Advisory
- CVE-2024-53261GHSA-rjjv-87mx-6x3h
@sveltejs/kit vulnerable to XSS on dev mode 404 page
- Affected:
- <2.8.3
- Fixed in:
- 2.8.3
- Source:
- OSV source · Advisory
- CVE-2024-53262GHSA-mh2x-fcqh-fmqv
@sveltejs/kit has unescaped error message included on error page
- Affected:
- <2.8.3
- Fixed in:
- 2.8.3
- Source:
- OSV source · Advisory
- CVE-2023-29008GHSA-gv7g-x59x-wf8f
SvelteKit framework has Insufficient CSRF protection for CORS requests
- Affected:
- <1.15.2
- Fixed in:
- 1.15.2
- Source:
- OSV source · Advisory
- CVE-2023-29003GHSA-5p75-vc5g-8rv2
SvelteKit vulnerable to Cross-Site Request Forgery
- Affected:
- <1.15.1
- Fixed in:
- 1.15.1
- Source:
- OSV source · Advisory
