Executive brief
SvelteKit is a web framework used to build server-rendered web applications. When a SvelteKit application iterates over URL search parameters in a server load function, parameter names are embedded unsanitized in the HTML sent to users. An attacker can craft a malicious URL containing JavaScript code in a parameter name and trick users into clicking the link, allowing arbitrary code execution in the victim's browser.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw in SvelteKit's search parameter tracking. When applications read search parameter keys/values inside server load functions (in +page.server.js or +layout.server.js), SvelteKit tracks these dependencies and embeds them in the boot script within the server-rendered HTML. The stringify_uses() function in packages/kit/src/runtime/server/utils.js does not sanitize parameter names before inclusion, allowing an attacker to inject malicious content. The attack requires user interaction (clicking a crafted link containing payload like `?</script><script>window.pwned=1</script>`) but requires no authentication or special privileges. An exploit executes arbitrary JavaScript in the victim's session context, potentially leading to session hijacking, credential theft, or data exfiltration. The fix is available in version 2.20.6 and later.
Affected products
- Svelte @sveltejs/kit 2.0.0 to 2.20.5
Timeline
- 2025-04-14: disclosed: Advisory published
- 2025-04-14: patched: Fix released in version 2.20.6