Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m56q-vw4c-c2cp

Опубликовано: 19 фев. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.1

Описание

Svelte SSR does not validate dynamic element tag names in <svelte:element>

When using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected.

Пакеты

Наименование

svelte

npm
Затронутые версииВерсия исправления

<= 5.51.4

5.51.5

EPSS

Процентиль: 1%
0.00011
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.6
redhat
около 1 месяца назад

svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

CVSS3: 5.4
nvd
около 1 месяца назад

svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

EPSS

Процентиль: 1%
0.00011
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79