VDB
Sign up
MEDIUM

GHSA-phwv-c562-gvmh

Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`

Quick fix

GHSA-phwv-c562-gvmh — svelte: upgrade to the fixed version with the command below.

npm install svelte@5.53.5

Details

The contents of `bind:innerText` and `bind:textContent` on `contenteditable` elements were not properly escaped. This could enable HTML injection and Cross-site Scripting (XSS) if rendering untrusted data as the binding's initial value on the server.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/svelte
Introduced in: 0Fixed in: 5.53.5
Fixnpm install svelte@5.53.5

References