VDB
Sign up
MEDIUM

GHSA-rcqx-6q8c-2c42

Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State

Quick fix

GHSA-rcqx-6q8c-2c42 — svelte: upgrade to the fixed version with the command below.

npm install svelte@5.55.7

Details

Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks.

You are vulnerable if all of the following is true: - you are using attribute spreading on a form element - you are using attribute spreading or allow a dynamic value for the `name` attribute on an input or button element within that form - both of these are simultaneously user-controllable

```svelte <form {...spread1}> <input {...spread2}> </form> ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/svelte
Introduced in: 0Fixed in: 5.55.7
Fixnpm install svelte@5.55.7

References