Vulnerabilities/

Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers

Severity:
Medium

Description

Errors from transformError were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from transformError.

Recommendation

Update the svelte package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
svelte
Anything's wrong? Let us know Last updated on February 26, 2026