Description
Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks.
Recommendation
Update the svelte package to the latest compatible version. Followings are version details:
- Affected version(s): <= 5.55.6
- Patched version(s): 5.55.7
References
Could your website be exposed too?
SmartScanner can check your website for Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State and gives you actionable findings to investigate.
Start a free scanRelated Issues
- wetty vulnerable to DOM XSS via file-download filename - CVE-2026-49864
- CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function - CVE-2026-26861
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes - CVE-2026-34405
You might also like:
See something that needs correcting? Let us knowUpdated June 09, 2026


