Executive brief
Svelecte is a popular select/dropdown component library for Svelte applications. The library fails to escape HTML characters in item names, allowing attackers to inject malicious HTML and JavaScript code that executes when users open the dropdown. Applications using Svelecte with user-supplied or untrusted item names are vulnerable to account takeover, data theft, and unauthorized actions performed on behalf of the user.
Technical details
Svelecte contains a cross-site scripting (XSS) vulnerability stemming from improper input neutralization (CWE-79, CWE-80). Item names are rendered directly as raw HTML by the default item renderer without escaping special characters like <, >, and &. This allows attackers to inject arbitrary HTML tags (e.g., <img>, <script>) and event handlers into dropdown items. The vulnerability requires low privileges and user interaction (opening the dropdown), with network-based attack vector. Exploitation is possible whenever applications render items from untrusted sources, including user-created content or external data. Content Security Policy restricts some attack vectors. The vulnerability was patched in version 3.16.3; all versions up to 3.16.2 are affected.
Affected products
- mskocik Svelecte <=3.16.2
Timeline
- 2023-08-14: disclosed
- 2023-08-14: patched: Version 3.16.3 released