CVE-2022-25875: Cross-site Scripting (XSS)

Published Jul 12, 2022
·
Updated

The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.

Other sources

The package svelte before 3.49.0 is vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.

Affected Software

2 affected componentsFixes available
npm/svelte<3.49.0
3.49.0
svelte Svelte Node.js<3.49.0

Event History

Jul 12, 2022
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionSeverityWeakness
Jul 13, 2022
Advisory Published
12:00 AM

Frequently Asked Questions

1

What is the severity of CVE-2022-25875?

CVE-2022-25875 is a high-severity vulnerability due to Cross-site Scripting (XSS) risks.

2

How do I fix CVE-2022-25875?

To fix CVE-2022-25875, upgrade the Svelte package to version 3.49.0 or above.

3

Which versions of Svelte are affected by CVE-2022-25875?

CVE-2022-25875 affects all Svelte versions before 3.49.0.

4

What type of vulnerability is CVE-2022-25875?

CVE-2022-25875 is a Cross-site Scripting (XSS) vulnerability.

5

How can CVE-2022-25875 be exploited?

CVE-2022-25875 can be exploited through improper input sanitization and escaping in server-side rendering when using certain objects.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203