VDB
Sign up
MEDIUM6.1

GHSA-wv8q-r932-8hc7

Svelte vulnerable to XSS when using objects during server-side rendering

Quick fix

GHSA-wv8q-r932-8hc7 — svelte: upgrade to the fixed version with the command below.

npm install svelte@3.49.0

Details

The package svelte before 3.49.0 is vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/svelte
Introduced in: 0Fixed in: 3.49.0
Fixnpm install svelte@3.49.0

References