Executive brief
Svelte is a popular JavaScript framework used to build web applications. The hydratable feature (used to enable server-side rendering with client-side interactivity) fails to properly sanitize promise-based content, allowing an attacker who can control input to inject malicious scripts into rendered pages. This could lead to theft of user session data, credentials, or other sensitive information displayed in the browser.
Technical details
This is a cross-site scripting (XSS) vulnerability in Svelte's hydratable function, which is used for server-side rendering (SSR) hydration. The vulnerability arises from improper stringification of promise contents, allowing attackers to inject arbitrary HTML/JavaScript when both synchronous and promise-based values are passed to the hydratable function with attacker-controlled input. The attack requires the application to use the experimental hydratable feature and pass attacker-controlled data that triggers hydration of a promise value. The vulnerability affects Svelte versions 5.46.0 through 5.55.6 and was patched in version 5.55.7.
Affected products
- Svelte Svelte 5.46.0 to 5.55.6
Timeline
- 2026-05-14: disclosed
- 2026-05-14: patched: Fixed in version 5.55.7