Vulnerabilities/

svelte is vulnerable to XSS with textarea bind:value

Severity:
High

Description

A server-side rendered <textarea> with two-way bound value does not have its value correctly escaped in the rendered HTML.

Recommendation

Update the svelte package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
svelte
Anything's wrong? Let us know Last updated on January 16, 2026