Svelte releases patches for 5 CVEs
Vulnerabilities affect devalue, svelte, @sveltejs/kit, and @sveltejs/adapter-node. Upgrade to specified versions immediately. Full details provided for each CVE.
See the latest news and media coverage for Svelte. We track all announcements, press releases, and industry mentions in real time, all in one place.
Last updated
In short: Svelte released major version 5 with a focus on runes for reactivity, while continuously updating SvelteKit and the sv CLI tool throughout 2026.
Vulnerabilities affect devalue, svelte, @sveltejs/kit, and @sveltejs/adapter-node. Upgrade to specified versions immediately. Full details provided for each CVE.
Highlights include improved Remote Functions, experimental async SSR, sv create from playgrounds, and a community showcase.
The post details new Svelte and SvelteKit features, community showcases, learning resources, and tools released in September 2025.
Svelte released Async Svelte with Remote Functions and updates to SvelteKit, language tools, and community showcases in August 2025.
An attacker can trigger a Cross Site Scripting of Node.js Svelte, via Hydratable Keys, in order to execute JavaScript code in the context of the site...
Aikido Security has reported its autonomous AI pentesting system found and reproduced a high-severity vulnerability affecting default SvelteKit deployments on Vercel, a common hosting platform...
Introduction Building feature-rich UI components like data tables or complex dashboards... Tagged with webdev, programming, javascript, svelte.
Svelte Attachments replace Svelte Actions. Just like with Svelte Actions, developers use attachments to provide code to run when a component or DOM element is...
Track Svelte and your other target companies to get real-time alerts and weekly summaries delivered straight to your inbox.
Browse news for competitors to Svelte and other trending companies.