Описание
Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7.
A flaw was found in Svelte, a web framework. An attacker could exploit a DOM clobbering vulnerability, which allows manipulation of the Document Object Model (DOM) to overwrite internal framework state on elements. This could potentially lead to Cross-Site Scripting (XSS) attacks, enabling the attacker to inject malicious scripts into web pages viewed by other users.
Отчет
Severity: Important This issue is classified as Important severity for deployments where untrusted content can influence Svelte-rendered markup, because:
- Conditions for Exploitation: The flaw is a DOM clobbering issue in the Svelte framework. Exploitation requires an application to render user-influenced markup using Svelte patterns where attacker-controlled HTML can clobber internal framework state (for example, unsafe spread of form or element attributes in a Svelte component). Remote exploitation requires a victim to interact with attacker-influenced content in the affected application (RH CVSS UI:R).
- Impact Limitations: The vulnerability is in a front-end UI framework dependency, not a standalone network service. Impact is limited to the security context of the application that embeds the vulnerable Svelte runtime.
- Upstream Stance: The upstream Svelte project and GHSA rate this issue Moderate (CVSS 5.3). Red Hat rates it Important with RH CVSS 8.1 where the affected product exposes a network-reachable or user-driven UI that could process untrusted markup through the vulnerable Svelte code paths. Red Hat build of Podman Desktop 1.0 and 1.1 ship a bundled Svelte dependency, but after engineering review Red Hat Product Security agrees these streams are not affected. Podman Desktop is an Electron-based desktop client, not a public-facing web application. There is no realistic path for an adversary to supply the user-influenced attribute spreads required to trigger DOM clobbering in this product context. The vulnerable Svelte code is not controllable by an adversary in the way the issue describes for typical web deployments.
Меры по смягчению последствий
For Red Hat build of Podman Desktop 1.0 and 1.1, no mitigation or dependency update is required. These streams are not affected; the bundled Svelte runtime is not exposed to adversary-controlled input in a way that enables this DOM clobbering flaw. Other products or components that embed Svelte in a context where untrusted markup can reach vulnerable spread patterns should plan to update the Svelte dependency to version 5.55.7 or later when applicable to their shipping model.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Build of Podman Desktop | rh-podman-desktop.git | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7.
Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State
EPSS
8.1 High
CVSS3