Home

Description

Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7.

PUBLISHED Reserved 2026-04-28 | Published 2026-06-09 | Updated 2026-06-09 | Assigner GitHub_M




MEDIUM: 5.3CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

< 5.55.7
affected

References

github.com/...svelte/security/advisories/GHSA-rcqx-6q8c-2c42

github.com/sveltejs/svelte/releases/tag/svelte@5.55.7

cve.org (CVE-2026-42573)

nvd.nist.gov (CVE-2026-42573)

Download JSON