VDB
Sign up
MEDIUM

GHSA-m56q-vw4c-c2cp

Svelte SSR does not validate dynamic element tag names in `<svelte:element>`

Quick fix

GHSA-m56q-vw4c-c2cp — svelte: upgrade to the fixed version with the command below.

npm install svelte@5.51.5

Details

When using `<svelte:element this={tag}>` in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/svelte
Introduced in: 0Fixed in: 5.51.5
Fixnpm install svelte@5.51.5

References