VDB
Sign up
—0.0

GHSA-rjjv-87mx-6x3h

@sveltejs/kit vulnerable to XSS on dev mode 404 page

Quick fix

GHSA-rjjv-87mx-6x3h — @sveltejs/kit: upgrade to the fixed version with the command below.

npm install @sveltejs/kit@2.8.3

Details

### Summary

"Unsanitized input from *the request URL* flows into `end`, where it is used to render an HTML page returned to the user. This may result in a Cross-Site Scripting attack (XSS)."

### Details

Source of potentially tainted data is in `packages/kit/src/exports/vite/dev/index.js`, line 437. This potentially tainted data is passed through a number of steps (which I could detail if you'd like) all the way down to line 91 in `packages/kit/src/exports/vite/utils.js`, which performs an operation that Snyk believes an attacker shouldn't be allowed to manipulate.

Another source of potentially tainted data (according to Snyk) comes from `‎packages/kit/src/exports/vite/utils.js`, line 30, col 30 (i.e., the `url` property of `req`). This potentially tainted data is passed through a number of steps (which I could detail if you'd like) all the way down line 91 in `packages/kit/src/exports/vite/utils.js`, which performs an operation that Snyk believes an attacker shouldn't be allowed to manipulate.

### PoC

Not provided

### Impact

Little to none. The Vite development is not exposed to the network by default. And even if someone were able to trick a developer into executing an XSS against themselves, a development database should not have any sensitive data.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@sveltejs/kit
Introduced in: 0Fixed in: 2.8.3
Fixnpm install @sveltejs/kit@2.8.3

References