Security: sveltejs/svelte
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
XSS via DOM Clobbering of Internal Framework StateGHSA-rcqx-6q8c-2c42 published
May 14, 2026 by elliott-with-the-longest-name-on-githubModerate -
ReDoS in `<svelte:element>` Tag ValidationGHSA-9rmh-mm8f-r9h6 published
May 14, 2026 by elliott-with-the-longest-name-on-githubModerate -
Cross-site scripting via spread attributes in Svelte SSRGHSA-pr6f-5x2q-rwfp published
May 14, 2026 by elliott-with-the-longest-name-on-githubModerate -
SSR XSS via Insecure Promise Serialization in hydratableGHSA-f3cj-j4f6-wq85 published
May 14, 2026 by elliott-with-the-longest-name-on-githubModerate -
XSS via HTML Comment Injection in SSR Error Boundary Hydration MarkersGHSA-qgvg-pr8v-6rr3 published
Feb 25, 2026 by elliott-with-the-longest-name-on-githubModerate -
XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`GHSA-phwv-c562-gvmh published
Feb 25, 2026 by elliott-with-the-longest-name-on-githubModerate -
Cross-site scripting via spread attributes in Svelte SSRGHSA-f7gr-6p89-r883 published
Feb 18, 2026 by elliott-with-the-longest-name-on-githubModerate -
Svelte SSR attribute spreading includes inherited properties from prototype chainGHSA-crpf-4hrx-3jrp published
Feb 18, 2026 by elliott-with-the-longest-name-on-githubModerate -
Svelte SSR does not validate dynamic element tag names in `<svelte:element>`GHSA-m56q-vw4c-c2cp published
Feb 18, 2026 by elliott-with-the-longest-name-on-githubModerate -
XSS in SSR `<option>` elementGHSA-h7h7-mm68-gmrc published
Feb 18, 2026 by elliott-with-the-longest-name-on-githubModerate