VDB
Sign up
MEDIUM

GHSA-h7h7-mm68-gmrc

Svelte affected by XSS in SSR `<option>` element

Quick fix

GHSA-h7h7-mm68-gmrc — svelte: upgrade to the fixed version with the command below.

npm install svelte@5.51.5

Details

In certain circumstances, the server-side rendering output of an `<option>` element does not properly escape its content, potentially allowing HTML injection in the SSR output. Client-side rendering is not affected.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/svelte
Introduced in: 5.39.3Fixed in: 5.51.5
Fixnpm install svelte@5.51.5

References