5.55.9
9 years ago
2 days ago
Known vulnerabilities in the svelte package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
svelte is a package for building web applications. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the rendering of attributes using spread syntax from untrusted data, which includes event handler properties in the HTML output. An attacker can execute arbitrary JavaScript code in the victim's browser by injecting malicious event handlers through user-controlled or external data. Note: This is only exploitable if the user's browser has JavaScript enabled and the hydration mechanism does not reach the vulnerable element before the event fires. How to fix Cross-site Scripting (XSS)? Upgrade | <5.55.7 |
svelte is a package for building web applications. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via improper serialization of Note: This is only exploitable if the experimental How to fix Cross-site Scripting (XSS)? Upgrade | >=5.46.0 <5.55.7 |
svelte is a package for building web applications. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the handling of attribute spreading and dynamic Note: This is only exploitable if attribute spreading is used on a form element and, within that form, attribute spreading or a dynamic value is allowed for the How to fix Cross-site Scripting (XSS)? Upgrade | <5.55.7 |
svelte is a package for building web applications. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | <5.53.5 |
svelte is a package for building web applications. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the server-side rendering process of the How to fix Cross-site Scripting (XSS)? Upgrade | >=5.39.3 <5.51.5 |
svelte is a package for building web applications. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the spread syntax when rendering attributes from untrusted data during server-side rendering. An attacker can execute arbitrary JavaScript in the context of a victim's browser by injecting malicious event handler properties through user-controlled or external data. How to fix Cross-site Scripting (XSS)? Upgrade | <5.51.5 |
svelte is a package for building web applications. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | <5.51.5 |
svelte is a package for building web applications. Affected versions of this package are vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in server-side rendering when attribute spreading is performed on elements. An attacker can inject unexpected attributes or cause errors in the rendered output by polluting the Note: This is only exploitable if the environment's How to fix Improperly Controlled Modification of Dynamically-Determined Object Attributes? Upgrade | <5.51.5 |