Executive brief
SveltyCMS is a headless content management system built with SvelteKit. An unvalidated SVG media upload feature allows remote attackers to inject malicious scripts that execute in users' browsers when the uploaded SVG files are viewed, potentially leading to session hijacking, credential theft, or defacement.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the SVG media upload handler within src/utils/media/media-service.server.ts. SVG uploads were not properly sanitized, allowing attackers to embed malicious scripts within SVG payloads that execute when the files are served or previewed. The root cause was that large SVG files could bypass the sanitization buffer, and no Content Security Policy restrictions were applied to the `/files/` serving routes. An attacker with upload privileges can remotely inject JavaScript payloads. The patch (commit 05b4f9efeb79e9d72a693232334d7529687f896f) implements sanitization via `bufferAndSanitizeSvg()`, enforces a strict 5 MiB size limit, and adds `script-src 'none'` CSP headers to file serving endpoints.
Affected products
- SveltyCMS SveltyCMS 0.0.6
Timeline
- 2026-09-18: disclosed
- 2026-08-07: patched: Patch commit 05b4f9efeb79e9d72a693232334d7529687f896f