Executive brief
Svelte is a popular frontend framework used to build interactive web applications. A vulnerability in its server-side rendering (SSR) feature could allow attackers to inject malicious code that executes in users' browsers if the application renders objects with custom functions. This could lead to theft of user session data, credentials, or malware distribution.
Technical details
Svelte before version 3.49.0 is vulnerable to cross-site scripting (XSS) due to improper input sanitization and inadequate escaping of object attributes during server-side rendering. The vulnerability exists in the attribute escaping logic and can be exploited by passing objects with a custom toString() function that returns malicious HTML/JavaScript. An attacker must control the objects passed to the Svelte component during SSR, typically through user-supplied input. When the framework calls toString() on these objects during HTML generation, the malicious payload is rendered unescaped into the HTML document. The fix, merged in pull request #7530, hardens attribute escaping during SSR and was released in version 3.49.0.
Affected products
- Svelte Svelte before 3.49.0
Timeline
- 2022-07-13: disclosed
- 2022-06-20: patched: Fix merged in PR #7530