VDB
Sign up
HIGH

GHSA-gw32-9rmw-qwww

svelte is vulnerable to XSS with textarea bind:value

Quick fix

GHSA-gw32-9rmw-qwww — svelte: upgrade to the fixed version with the command below.

npm install svelte@3.59.2

Details

### Summary

A server-side rendered `<textarea>` with two-way bound value does not have its value correctly escaped in the rendered HTML.

### Details

In SSR, `<textarea bind:value={...}>` does not have its value escaped when it is rendered into the HTML as `<textarea>...</textarea>`.

### PoC

Put this in a server-side-rendered Svelte component:

``` <script> let value = `test'"></textarea><script` + `>alert('BIM');</sc` + `ript>`; </script>

<textarea bind:value /> ```

### Impact

- Only affects SSR - Needs a `<textarea bind:value>` filled by user content via two-way binding

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/svelte
Introduced in: 3.0.0Fixed in: 3.59.2
Fixnpm install svelte@3.59.2

References