MEDIUM
GHSA-qgvg-pr8v-6rr3
Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers
Quick fix
GHSA-qgvg-pr8v-6rr3 — svelte: upgrade to the fixed version with the command below.
npm install svelte@5.53.5Details
Errors from `transformError` were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from `transformError`.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/sveltejs/svelte/security/advisories/GHSA-qgvg-pr8v-6rr3[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-27902[ADVISORY]
- https://github.com/sveltejs/svelte/commit/0298e979371bb583855c9810db79a70a551d22b9[WEB]
- https://github.com/sveltejs/svelte[PACKAGE]
- https://github.com/sveltejs/svelte/releases/tag/svelte@5.53.5[WEB]