VDB
Sign up
MEDIUM

GHSA-pr6f-5x2q-rwfp

Svelte SSR vulnerable to cross-site scripting via spread attributes

Quick fix

GHSA-pr6f-5x2q-rwfp — svelte: upgrade to the fixed version with the command below.

npm install svelte@5.55.7

Details

When using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers. Note that this vulnerability _only_ triggers if the user's browser has JavaScript enabled but Svelte's hydration mechanism does not reach the vulnerable element before the event fires.

This is similar to but different from [CVE-2026-27121](https://nvd.nist.gov/vuln/detail/CVE-2026-27121).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/svelte
Introduced in: 0Fixed in: 5.55.7
Fixnpm install svelte@5.55.7

References