Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qgvg-pr8v-6rr3

Опубликовано: 26 фев. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers

Errors from transformError were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from transformError.

Пакеты

Наименование

svelte

npm
Затронутые версииВерсия исправления

>= 5.53.0, < 5.53.5

5.53.5

EPSS

Процентиль: 9%
0.00032
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.2
redhat
30 дней назад

Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from `transformError`. Version 5.53.5 fixes the issue.

CVSS3: 5.4
nvd
30 дней назад

Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from `transformError`. Version 5.53.5 fixes the issue.

EPSS

Процентиль: 9%
0.00032
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-79