Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h7h7-mm68-gmrc

Опубликовано: 19 фев. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.1

Описание

Svelte affected by XSS in SSR <option> element

In certain circumstances, the server-side rendering output of an <option> element does not properly escape its content, potentially allowing HTML injection in the SSR output. Client-side rendering is not affected.

Пакеты

Наименование

svelte

npm
Затронутые версииВерсия исправления

>= 5.39.3, < 5.51.5

5.51.5

EPSS

Процентиль: 1%
0.00011
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.6
redhat
около 1 месяца назад

svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the server-side rendering output of an <option> element does not properly escape its content, potentially allowing HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

CVSS3: 5.4
nvd
около 1 месяца назад

svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the server-side rendering output of an <option> element does not properly escape its content, potentially allowing HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

EPSS

Процентиль: 1%
0.00011
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79