Junglewise Threat Intelligence

CVE-2023-38687: Svelecte item names cross-site scripting

CVE-2023-38687 · Severity: low · CVSS 3.1 · Published 2023-08-14

Vendors: npm.

Executive brief

Svelecte is a popular select/dropdown component library for Svelte applications. The library fails to escape HTML characters in item names, allowing attackers to inject malicious HTML and JavaScript code that executes when users open the dropdown. Applications using Svelecte with user-supplied or untrusted item names are vulnerable to account takeover, data theft, and unauthorized actions performed on behalf of the user.

Technical details

Svelecte contains a cross-site scripting (XSS) vulnerability stemming from improper input neutralization (CWE-79, CWE-80). Item names are rendered directly as raw HTML by the default item renderer without escaping special characters like <, >, and &. This allows attackers to inject arbitrary HTML tags (e.g., <img>, <script>) and event handlers into dropdown items. The vulnerability requires low privileges and user interaction (opening the dropdown), with network-based attack vector. Exploitation is possible whenever applications render items from untrusted sources, including user-created content or external data. Content Security Policy restricts some attack vectors. The vulnerability was patched in version 3.16.3; all versions up to 3.16.2 are affected.

Affected products

  • mskocik Svelecte <=3.16.2

Timeline

  • 2023-08-14: disclosed
  • 2023-08-14: patched: Version 3.16.3 released

References