mediumVulnerability

GHSA-f3cj-j4f6-wq85

Contents of `hydratable` promises were not properly stringified, potentially leading to an XSS exploit. You are vulnerable if all of the following is true: - you are using `hydratable` (an experimental feature at the time of this report) - you are passing attacker-controlled input such that a synchronous value is hydrated, then a promise value, e.g. `hydratable('someKey', () => [synchronousValue, promiseValue])`

Properties

ghsa_id
GHSA-f3cj-j4f6-wq85
severity
medium
summary
Svelte: SSR XSS via Insecure Promise Serialization in hydratable
cve_id
GHSA-f3cj-j4f6-wq85
is_ghsa_only
true
ghsa_published
2026-05-14T20:30:09Z
source_url
https://github.com/advisories/GHSA-f3cj-j4f6-wq85
ghsa_updated
2026-05-14T20:30:13Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/svelte

AFFECTS (1)

[Software]npm/svelte

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-f3cj-j4f6-wq85 — Ninja Signal Threat Intelligence | Ninja Signal