SSR XSS via Insecure Promise Serialization in hydratable
Svelte security advisories
All 13 advisories Svelte has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 1311 carry a CVE
- high
- 1
- medium
- 12
- Fix in the archive
- 10of 13 matched to a release
- Oldest
- 30 Aug 20242 years ago
3 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productCross-site scripting via spread attributes in Svelte SSR
ReDoS in `<svelte:element>` Tag Validation
XSS via DOM Clobbering of Internal Framework State
XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`
XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers
XSS in SSR `<option>` element
Svelte SSR does not validate dynamic element tag names in `<svelte:element>`
Svelte SSR attribute spreading includes inherited properties from prototype chain
Cross-site scripting via spread attributes in Svelte SSR
XSS with textarea bind:value
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in svelte
Potential XSS vulnerability due to improper HTML attribute escaping