CVE-2026-93505: SveltyCMS SVG Media Upload media-service.server.ts cross site scripting
A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The patch is named 05b4f9efeb79e9d72a693232334d7529687f896f. Applying a patch is the recommended action to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SveltyCMSto a version that resolves this vulnerability.Fixed in 0.0.6Patch 05b4f9efeb79e9d72a693232334d7529687f896f
Event History
Frequently Asked Questions
What access and interaction are required to exploit this issue?
The attacker needs low-privileged access and must induce user interaction. The attack can be initiated remotely.
Which component should be prioritized for remediation?
The affected area is the SVG Media Upload component, involving src/utils/media/media-service.server.ts in SveltyCMS 0.0.6.
What should teams do if they are vulnerable?
Apply patch 05b4f9efeb79e9d72a693232334d7529687f896f. The available data identifies applying this patch as the recommended remediation.