Junglewise Threat Intelligence

Svelte SSR XSS via Insecure Promise Serialization in hydratable

Severity: medium · CVSS 5.3 · Published 2026-05-14

Technologies: svelte (npm). Vendors: Svelte, npm.

Executive brief

A vulnerability in the Svelte web framework could allow attackers to inject malicious scripts into web pages. This occurs when the framework's experimental 'hydratable' feature incorrectly handles data sent from the server to the browser. If exploited, an attacker could execute code in a user's browser, potentially leading to unauthorized actions or data theft.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Svelte's Server-Side Rendering (SSR) implementation. The root cause is the improper stringification of contents within 'hydratable' promises during serialization. An attacker can exploit this by providing malicious input that is processed through the hydratable function, specifically when a synchronous value is followed by a promise value. This allows for the injection of arbitrary scripts into the rendered HTML. The vulnerability affects Svelte versions 5.46.0 through 5.55.6 and is fixed in version 5.55.7. Exploitation requires the use of the experimental hydratable feature and the presence of attacker-controlled input in the hydration logic.

Affected products

  • sveltejs svelte >= 5.46.0, <= 5.55.6

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: patched: Fixed in version 5.55.7

References

Related threats