Description
A potential XSS vulnerability exists in Svelte for versions prior to 4.2.19.
Recommendation
Update the svelte package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.2.19
- Patched version(s): 4.2.19
References
Could your website be exposed too?
SmartScanner can check your website for Svelte has a potential mXSS vulnerability due to improper HTML escaping and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Slim Select has potential Cross-site Scripting issue - CVE-2024-9440
- MCPHub has an Improper Authorization vulnerability via its handleSseConnection function - CVE-2025-11287
- Marp Core allows XSS by improper neutralization of HTML sanitization - CVE-2024-56510
- @cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability - CVE-2024-34345
You might also like:
See something that needs correcting? Let us knowUpdated August 30, 2024


