PT-2022-17581 · Svelte · Svelte

Maurício Kishi

·

Published

2022-07-12

·

Updated

2022-07-19

·

CVE-2022-25875

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions svelte versions prior to 3.49.0
Description The issue arises from improper input sanitization and improper escape of attributes when using objects during Server-Side Rendering (SSR), leading to Cross-site Scripting (XSS). This can be exploited via objects with a custom toString() function.
Recommendations For versions prior to 3.49.0, update to version 3.49.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of objects with custom toString() functions in SSR until a patch is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25875
GHSA-WV8Q-R932-8HC7
SNYK-JS-SVELTE-2931080

Affected Products

Svelte