svelte
34 known vulnerabilities · 0 critical · 2 high
Svelte SSR does not validate dynamic element tag names in `<svelte:element>`
Svelte SSR attribute spreading includes inherited properties from prototype chain
svelte is vulnerable to XSS with textarea bind:value
Svelte affected by cross-site scripting via spread attributes in Svelte SSR
Svelte: ReDoS in `<svelte:element>` Tag Validation
Svelte: SSR XSS via Insecure Promise Serialization in hydratable
Svelte SSR vulnerable to cross-site scripting via spread attributes
Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State
Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`
Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers
Svelte vulnerable to XSS when using objects during server-side rendering
Memory exhaustion in SvelteKit remote form deserialization (experimental only)
`sveltekit-superforms` has Prototype Pollution in `parseFormData` function of `formData.js`
Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own properties
SvelteKit framework has Insufficient CSRF protection for CORS requests
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
CPU exhaustion in SvelteKit remote form deserialization (experimental only)
Svelte devalue: DoS via sparse array deserialization
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
Malicious code in svelte-toasty (npm)
Malicious code in mapkit-example-svelte (npm)
SvelteKit has deserialization expansion in unvalidated `form` remote function leading to Denial of Service (experimental only)
@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
Malicious code in svelte-local-storage (npm)
Malicious code in svelte-hms-world (npm)
Malicious code in svelte-monorepo (npm)
@sveltejs/kit: `query.batch` cross-talk
Malicious code in pysvelte (npm)
Malicious code in svelte-autocomplete-select (npm)