Vulnerabilities/

@sveltejs/kit vulnerable to XSS on dev mode 404 page

Severity:
Low

Description

“Unsanitized input from the request URL flows into end, where it is used to render an HTML page returned to the user. This may result in a Cross-Site Scripting attack (XSS).”

Recommendation

Update the @sveltejs/kit package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@sveltejs/kit
Anything's wrong? Let us know Last updated on January 22, 2025

This issue is available in SmartScanner Professional

See Pricing