GHSA-pr6f-5x2q-rwfp
Svelte SSR vulnerable to cross-site scripting via spread attributes
Quick fix
GHSA-pr6f-5x2q-rwfp — svelte: upgrade to the fixed version with the command below.
npm install svelte@5.55.7Details
When using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers. Note that this vulnerability _only_ triggers if the user's browser has JavaScript enabled but Svelte's hydration mechanism does not reach the vulnerable element before the event fires.
This is similar to but different from [CVE-2026-27121](https://nvd.nist.gov/vuln/detail/CVE-2026-27121).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/sveltejs/svelte/security/advisories/GHSA-pr6f-5x2q-rwfp[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-27121[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-42599[ADVISORY]
- https://github.com/sveltejs/svelte[PACKAGE]
- https://github.com/sveltejs/svelte/releases/tag/svelte%405.55.7[WEB]