Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-15265

Опубликовано: 15 янв. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside a to terminate the script and inject arbitrary JavaScript. This enables remote script execution in users' browsers, with potential for session theft and account compromise. This issue affects Svelte: from 5.46.0 before 5.46.3.

A flaw was found in Svelte. A remote attacker can exploit this Cross-Site Scripting (XSS) vulnerability during asynchronous hydration by providing specially crafted input. This input, when processed, allows for the injection of arbitrary JavaScript into a user's browser due to improper escaping of attacker-controlled keys within a script block. Successful exploitation can lead to remote script execution, potentially resulting in session theft and account compromise.

Отчет

This vulnerability is rated Moderate for Red Hat products that incorporate Svelte versions 5.46.0 through 5.46.2 and utilize server-side rendering (SSR) with async hydration. Exploitation requires an attacker to control keys passed to hydratable components, leading to script injection and remote script execution in client browsers. This could result in session theft and account compromise for users interacting with affected applications.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Podman Desktop - Tech Previewrhdesktop/rh-podman-desktop-ext-bootc-rhel10Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2430177Svelte: Svelte: Remote script execution via Cross-Site Scripting (XSS) in async hydration

EPSS

Процентиль: 24%
0.00313
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
8 месяцев назад

An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside a <script> block without HTML‑safe escaping, allowing </script> to terminate the script and inject arbitrary JavaScript. This enables remote script execution in users' browsers, with potential for session theft and account compromise. This issue affects Svelte: from 5.46.0 before 5.46.3.

github
8 месяцев назад

svelte vulnerable to Cross-site Scripting

EPSS

Процентиль: 24%
0.00313
Низкий

6.1 Medium

CVSS3