@sveltejs/kit@2.20.4 vulnerabilities

SvelteKit is the fastest way to build Svelte apps

  • latest version

    2.20.7

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    2 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @sveltejs/kit package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    @sveltejs/kit is a SvelteKit framework and CLI

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) when processing a load() function call. An attacker can execute scripts in the context of the user's browser session by convincing a user to follow a malicious link via URL that contains a script. If an application's invocation of load() iterates over the tracked search params in event.url.searchParams it will retrieve and render the contents of each one, including the malicious URL.

    How to fix Cross-site Scripting (XSS)?

    Upgrade @sveltejs/kit to version 2.20.6 or higher.

    >=2.0.0 <2.20.6