VDB
Sign up
MEDIUM

GHSA-f3cj-j4f6-wq85

Svelte: SSR XSS via Insecure Promise Serialization in hydratable

Quick fix

GHSA-f3cj-j4f6-wq85 — svelte: upgrade to the fixed version with the command below.

npm install svelte@5.55.7

Details

Contents of `hydratable` promises were not properly stringified, potentially leading to an XSS exploit. You are vulnerable if all of the following is true: - you are using `hydratable` (an experimental feature at the time of this report) - you are passing attacker-controlled input such that a synchronous value is hydrated, then a promise value, e.g. `hydratable('someKey', () => [synchronousValue, promiseValue])`

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/svelte
Introduced in: 5.46.0Fixed in: 5.55.7
Fixnpm install svelte@5.55.7

References