Catalog / Svelte

Svelte security advisories

All 13 advisories Svelte has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
1311 carry a CVE
high
1
medium
12
Fix in the archive
10of 13 matched to a release
Oldest
30 Aug 20242 years ago

3 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2026-27125medium

Svelte SSR attribute spreading includes inherited properties from prototype chain

GHSA-crpf-4hrx-3jrpFixed in 5.51.5
CVE-2025-15265medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in svelte

GHSA-6738-r8g5-qwp3Fixed in 5.46.4, not held here
CVE-2024-45047medium

Potential XSS vulnerability due to improper HTML attribute escaping

GHSA-8266-84wp-wv5cFixed in 4.2.19, not held here