Vulnerabilities/

Svelte: SSR XSS via Insecure Promise Serialization in hydratable

Severity:
Medium

Description

Contents of hydratable promises were not properly stringified, potentially leading to an XSS exploit. You are vulnerable if all of the following is true:

Recommendation

Update the svelte package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
svelte
Anything's wrong? Let us know Last updated on May 14, 2026