Description
In server-side rendering, attribute spreading on elements (e.g. <div {...attrs}>) enumerates inherited properties from the object’s prototype chain rather than only own properties. In environments where Object.prototype has already been polluted — a precondition outside of Svelte’s control — this can cause unexpected attributes to appear in SSR output or cause SSR to throw errors.
Recommendation
Update the svelte package to the latest compatible version. Followings are version details:
- Affected version(s): <= 5.51.4
- Patched version(s): 5.51.5
References
Could your website be exposed too?
SmartScanner can check your website for Svelte SSR attribute spreading includes inherited properties from prototype chain and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Svelte affected by XSS in SSR `<option>` element - CVE-2026-27119
- Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers - CVE-2026-27902
- Svelte affected by cross-site scripting via spread attributes in Svelte SSR - CVE-2026-27121
- JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection - CVE-2026-46625


