MEDIUM
GHSA-f3cj-j4f6-wq85
Svelte: SSR XSS via Insecure Promise Serialization in hydratable
Quick fix
GHSA-f3cj-j4f6-wq85 — svelte: upgrade to the fixed version with the command below.
npm install svelte@5.55.7Details
Contents of `hydratable` promises were not properly stringified, potentially leading to an XSS exploit. You are vulnerable if all of the following is true: - you are using `hydratable` (an experimental feature at the time of this report) - you are passing attacker-controlled input such that a synchronous value is hydrated, then a promise value, e.g. `hydratable('someKey', () => [synchronousValue, promiseValue])`
Are you affected?
Enter the version of the package you're using.