{"id":"GHSA-6738-r8g5-qwp3","summary":"svelte vulnerable to Cross-site Scripting","details":"## Summary\n\nAn XSS vulnerability exists in Svelte 5.46.0-2 resulting from improper escaping of `hydratable` keys. If these keys incorporate untrusted user input, arbitrary JavaScript can be injected into server-rendered HTML.\n\n## Details\n\nWhen using the [`hydratable`](https://svelte.dev/docs/svelte/hydratable) function, the first argument is used as a key to uniquely identify the data, such that the value is not regenerated in the browser.\n\nThis key is embedded into a `\u003cscript\u003e` block in the server-rendered `\u003chead\u003e` without escaping unsafe characters. A malicious key can break out of the script context and inject arbitrary JavaScript into the HTML response.\n\n## Impact\n\nThis is a cross-site scripting vulnerability affecting applications that have the `experimental.async` flag enabled and use `hydratable` with keys incorporating untrusted user input. \n\n- **Impact**: Arbitrary JS execution in the client’s browser.\n- **Exploitability**: Remote, single-request if key is attacker-controlled.\n- **Typical Outcomes**:\n  - Session/token theft\n  - DOM defacement\n  - CSRF bypass via injected JS\n  - Account takeover depending on cookie/session strategy\n\nAffected applications should upgrade to a patched version immediately.","aliases":["CVE-2025-15265"],"modified":"2026-02-03T03:17:21.713697Z","published":"2026-01-15T20:13:33Z","database_specific":{"nvd_published_at":"2026-01-15T20:16:03Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-01-15T20:13:33Z"},"references":[{"type":"WEB","url":"https://github.com/sveltejs/svelte/security/advisories/GHSA-6738-r8g5-qwp3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15265"},{"type":"WEB","url":"https://github.com/sveltejs/svelte/commit/ef81048e238844b729942441541d6dcfe6c8ccca"},{"type":"WEB","url":"https://fluidattacks.com/advisories/lydian"},{"type":"PACKAGE","url":"https://github.com/sveltejs/svelte"},{"type":"WEB","url":"https://github.com/sveltejs/svelte/releases/tag/svelte%405.46.4"}],"affected":[{"package":{"name":"svelte","ecosystem":"npm","purl":"pkg:npm/svelte"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.46.0"},{"fixed":"5.46.4"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 5.46.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-6738-r8g5-qwp3/GHSA-6738-r8g5-qwp3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}