CVE-2026-42599

MEDIUM

Cross-site scripting via spread attributes in Svelte SSR

Title source: cna
STIX 2.1

Description

Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers. Note that this vulnerability only triggers if the user's browser has JavaScript enabled but Svelte's hydration mechanism does not reach the vulnerable element before the event fires. This issue has been patched in version 5.55.7.

References (2)

Core 2
Core References

Scores

CVSS v3 6.1
EPSS 0.0017
EPSS Percentile 6.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (3)
npm/svelte 0 - 5.55.7npm
svelte/svelte < 5.55.7
sveltejs/svelte < 5.55.7
Published Jun 09, 2026
Tracked Since Jun 09, 2026