Executive brief
Svelte is a popular JavaScript framework used to build interactive web applications. This vulnerability allows attackers to inject malicious HTML code into server-rendered option elements, which could lead to cross-site scripting attacks and compromise of website content. Only applications using server-side rendering are affected; client-side rendering is not impacted.
Technical details
This is a cross-site scripting (XSS) vulnerability (CWE-79) in Svelte's server-side rendering (SSR) implementation where the content of HTML `<option>` elements is not properly escaped. An attacker with high privileges and under specific conditions can inject unescaped HTML into the SSR output, leading to HTML injection and potential XSS attacks. The vulnerability requires network access, high attack complexity, high privileges, and attack requirements to be present. Client-side rendering is unaffected. The vulnerability was patched in version 5.51.5.
Affected products
- Svelte Svelte 5.39.3 to 5.51.4
Timeline
- 2026-02-19: disclosed
- 2026-02-19: patched: Version 5.51.5