VDB
Sign up
MEDIUM

GHSA-qgvg-pr8v-6rr3

Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers

Quick fix

GHSA-qgvg-pr8v-6rr3 — svelte: upgrade to the fixed version with the command below.

npm install svelte@5.53.5

Details

Errors from `transformError` were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from `transformError`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/svelte
Introduced in: 5.53.0Fixed in: 5.53.5
Fixnpm install svelte@5.53.5

References